EEF-CVE-2026-21619

Source
https://cna.erlef.org/osv/EEF-CVE-2026-21619.html
Import Source
https://cna.erlef.org/osv/EEF-CVE-2026-21619.json
JSON Data
https://api.osv.dev/v1/vulns/EEF-CVE-2026-21619
Aliases
Published
2026-02-27T17:57:11.513Z
Modified
2026-07-30T18:21:59.172007Z
Severity
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Unsafe Deserialization of Erlang Terms in hex_core
Details

Summary

Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4.

This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.

Database specific
{
    "capec_ids": [
        "CAPEC-586",
        "CAPEC-130"
    ],
    "cwe_ids": [
        "CWE-400",
        "CWE-502"
    ],
    "cpe_ids": [
        "cpe:2.3:a:hexpm:hex_core:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:hexpm:hex:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:erlang:rebar3:*:*:*:*:*:*:*:*"
    ]
}
References
Credits
    • Michael Lubas / Paraxial.io - FINDER
    • Jonatan Männchen / EEF - REMEDIATION_DEVELOPER
    • Eric Meadows-Jönsson / Hex.pm - REMEDIATION_REVIEWER

Affected packages

Hex
hex_core

Package

Name
hex_core
Purl
pkg:hex/hex_core

Affected ranges

Type
SEMVER
Events
Introduced
0.1.0
Fixed
0.12.1

Affected versions

0.*
0.1.0
0.1.1
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.6.10
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-21619.json"
Git
github.com/hexpm/hex_core

Affected ranges

Type
GIT
Repo
https://github.com/hexpm/hex_core
Events

Affected versions

v0.*
v0.1.0
v0.1.1
v0.10.0
v0.10.1
v0.10.2
v0.10.3
v0.11.0
v0.12.0
v0.2.0
v0.2.1
v0.3.0
v0.4.0
v0.5.0
v0.6.0
v0.6.1
v0.6.3
v0.6.4
v0.6.5
v0.6.6
v0.6.7
v0.6.8
v0.6.9
v0.7.0
v0.7.1
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.8.4
v0.9.0

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-21619.json"
github.com/hexpm/hex

Affected ranges

Type
GIT
Repo
https://github.com/hexpm/hex
Events

Affected versions

v2.*
v2.3.0
v2.3.1

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-21619.json"
github.com/erlang/rebar3

Affected ranges

Type
GIT
Repo
https://github.com/erlang/rebar3
Events

Affected versions

3.*
3.11.0
3.11.1
3.12.0
3.13.0
3.14.0
3.14.0-rc1
3.14.0-rc2
3.14.1
3.14.2
3.14.4
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.19.0
3.20.0
3.21.0
3.22.0
3.22.1
3.23.0
3.24.0
3.25.0
3.25.1
3.26.0
3.9.1

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-21619.json"