EEF-CVE-2026-21619

Source
https://cna.erlef.org/osv/EEF-CVE-2026-21619.html
Import Source
https://cna.erlef.org/osv/EEF-CVE-2026-21619.json
JSON Data
https://api.osv.dev/v1/vulns/EEF-CVE-2026-21619
Aliases
Published
2026-02-27T17:57:11.513Z
Modified
2026-02-28T05:56:20.371755Z
Severity
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Unsafe Deserialization of Erlang Terms in hex_core
Details

Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hexcore (hexapi modules), hexpm hex (mixhexapi modules), erlang rebar3 (r3hexapi modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hexapi.erl, src/mixhexapi.erl, apps/rebar/src/vendored/r3hexapi.erl and program routines hexcore:request/4, mixhexapi:request/4, r3hexapi:request/4.

This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.

Database specific
{
    "capec_ids": [
        "CAPEC-586",
        "CAPEC-130"
    ],
    "cwe_ids": [
        "CWE-400",
        "CWE-502"
    ],
    "cpe_ids": [
        "cpe:2.3:a:hexpm:hex_core:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:hexpm:hex:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:erlang:rebar3:*:*:*:*:*:*:*:*"
    ]
}
References
Credits
    • Michael Lubas / Paraxial.ia - FINDER
    • Jonatan Männchen / EEF - REMEDIATION_DEVELOPER
    • Eric Meadows-Jönsson / Hex.pm - REMEDIATION_REVIEWER

Affected packages

Hex
hex_core

Package

Name
hex_core
Purl
pkg:hex/hex_core

Affected ranges

Type
SEMVER
Events
Introduced
0.1.0
Fixed
0.12.1

Affected versions

0.*
0.1.0
0.1.1
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.6.10
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-21619.json"
Git
github.com/hexpm/hex_core

Affected ranges

Type
GIT
Repo
https://github.com/hexpm/hex_core
Events

Affected versions

v0.*
v0.1.0
v0.1.1
v0.10.0
v0.10.1
v0.10.2
v0.10.3
v0.11.0
v0.12.0
v0.2.0
v0.2.1
v0.3.0
v0.4.0
v0.5.0
v0.6.0
v0.6.1
v0.6.3
v0.6.4
v0.6.5
v0.6.6
v0.6.7
v0.6.8
v0.6.9
v0.7.0
v0.7.1
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.8.4
v0.9.0

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-21619.json"
github.com/hexpm/hex

Affected ranges

Type
GIT
Repo
https://github.com/hexpm/hex
Events

Affected versions

v2.*
v2.3.0
v2.3.1

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-21619.json"
github.com/erlang/rebar3

Affected ranges

Type
GIT
Repo
https://github.com/erlang/rebar3
Events

Affected versions

3.*
3.11.0
3.11.1
3.12.0
3.13.0
3.14.0
3.14.0-rc1
3.14.0-rc2
3.14.1
3.14.2
3.14.4
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.19.0
3.20.0
3.21.0
3.22.0
3.22.1
3.23.0
3.24.0
3.25.0
3.25.1
3.26.0
3.9.1

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-21619.json"