Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4.
This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4. This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0. | |
| Title | Unsafe Deserialization of Erlang Terms in hex_core | |
| First Time appeared |
Erlang
Erlang rebar3 Hexpm Hexpm hex Hexpm hex Core |
|
| Weaknesses | CWE-400 CWE-502 |
|
| CPEs | cpe:2.3:a:erlang:rebar3:*:*:*:*:*:*:*:* cpe:2.3:a:hexpm:hex:*:*:*:*:*:*:*:* cpe:2.3:a:hexpm:hex_core:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Erlang
Erlang rebar3 Hexpm Hexpm hex Hexpm hex Core |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-02-27T19:08:57.019Z
Reserved: 2026-01-01T03:46:45.933Z
Link: CVE-2026-21619
Updated: 2026-02-27T19:08:54.436Z
Status : Received
Published: 2026-02-27T18:16:11.373
Modified: 2026-02-27T18:16:11.373
Link: CVE-2026-21619
No data.
OpenCVE Enrichment
No data.