This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hx9w-f2w9-9g96 | hex_core has Unsafe Deserialization of Erlang Terms |
Mon, 06 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 23 Mar 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hex
Hex hex Hex hex Core |
|
| CPEs | cpe:2.3:a:hex:hex:*:*:*:*:*:*:*:* cpe:2.3:a:hex:hex_core:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Hex
Hex hex Hex hex Core |
|
| Metrics |
cvssV3_1
|
Fri, 27 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4. This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0. | |
| Title | Unsafe Deserialization of Erlang Terms in hex_core | |
| First Time appeared |
Erlang
Erlang rebar3 Hexpm Hexpm hex Hexpm hex Core |
|
| Weaknesses | CWE-400 CWE-502 |
|
| CPEs | cpe:2.3:a:erlang:rebar3:*:*:*:*:*:*:*:* cpe:2.3:a:hexpm:hex:*:*:*:*:*:*:*:* cpe:2.3:a:hexpm:hex_core:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Erlang
Erlang rebar3 Hexpm Hexpm hex Hexpm hex Core |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-04-06T16:44:11.526Z
Reserved: 2026-01-01T03:46:45.933Z
Link: CVE-2026-21619
Updated: 2026-02-27T19:08:54.436Z
Status : Modified
Published: 2026-02-27T18:16:11.373
Modified: 2026-04-06T17:17:07.037
Link: CVE-2026-21619
No data.
OpenCVE Enrichment
Updated: 2026-04-16T00:00:14Z
Github GHSA