CVE-2026-21619

Source
https://cve.org/CVERecord?id=CVE-2026-21619
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21619.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-21619
Aliases
Downstream
Published
2026-02-27T17:57:11.513Z
Modified
2026-07-15T01:49:20.144532955Z
Severity
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Unsafe Deserialization of Erlang Terms in hex_core
Details

Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hexcore (hexapi modules), hexpm hex (mixhexapi modules), erlang rebar3 (r3hexapi modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hexapi.erl, src/mixhexapi.erl, apps/rebar/src/vendored/r3hexapi.erl and program routines hexcore:request/4, mixhexapi:request/4, r3hexapi:request/4.

This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.

Database specific
{
    "cwe_ids": [
        "CWE-400",
        "CWE-502"
    ],
    "cna_assigner": "EEF",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "eb327f8edfe45507351e38cc0805aa12fa647f0b"
                },
                {
                    "fixed": "cdf726095bca85ad2549d146df1e831ae93c2b13"
                },
                {
                    "introduced": "314546ac432229518714cc8e3336e916b9da6305"
                },
                {
                    "fixed": "636739f3322514e9303ca335fb630696fcbb3c95"
                },
                {
                    "introduced": "209c02ec57c2cc3207ee0174c3af3675b8dc8f79"
                },
                {
                    "fixed": "1d4478f527e373de0b225951e53115450e0d9b9d"
                }
            ]
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21619.json"
}
References

Affected packages

Git / github.com/erlang/rebar3

Affected ranges

Type
GIT
Repo
https://github.com/erlang/rebar3
Events
Database specific
{
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:erlang:rebar3:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.9.1"
        },
        {
            "fixed": "3.27.0"
        }
    ]
}
Type
GIT
Repo
https://github.com/hexpm/hex
Events
Database specific
{
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:hex:hex:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.3.0"
        },
        {
            "fixed": "2.3.2"
        }
    ]
}
Type
GIT
Repo
https://github.com/hexpm/hex_core
Events
Database specific
{
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:hex:hex_core:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0.1.0"
        },
        {
            "fixed": "0.12.1"
        }
    ]
}

Affected versions

3.*
3.11.0
3.11.1
3.12.0
3.13.0
3.14.0
3.14.0-rc1
3.14.0-rc2
3.14.1
3.14.2
3.14.4
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.19.0
3.20.0
3.21.0
3.22.0
3.22.1
3.23.0
3.24.0
3.25.0
3.25.1
3.26.0
3.9.1
v0.*
v0.1.0
v0.1.1
v0.10.0
v0.10.1
v0.10.2
v0.10.3
v0.11.0
v0.12.0
v0.2.0
v0.2.1
v0.3.0
v0.4.0
v0.5.0
v0.6.0
v0.6.1
v0.6.3
v0.6.4
v0.6.5
v0.6.6
v0.6.7
v0.6.8
v0.6.9
v0.7.0
v0.7.1
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.8.4
v0.9.0
v2.*
v2.3.0
v2.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21619.json"