Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4.

This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 27 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Description Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4. This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.
Title Unsafe Deserialization of Erlang Terms in hex_core
First Time appeared Erlang
Erlang rebar3
Hexpm
Hexpm hex
Hexpm hex Core
Weaknesses CWE-400
CWE-502
CPEs cpe:2.3:a:erlang:rebar3:*:*:*:*:*:*:*:*
cpe:2.3:a:hexpm:hex:*:*:*:*:*:*:*:*
cpe:2.3:a:hexpm:hex_core:*:*:*:*:*:*:*:*
Vendors & Products Erlang
Erlang rebar3
Hexpm
Hexpm hex
Hexpm hex Core
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-02-27T19:08:57.019Z

Reserved: 2026-01-01T03:46:45.933Z

Link: CVE-2026-21619

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-27T18:16:11.373

Modified: 2026-02-27T18:16:11.373

Link: CVE-2026-21619

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses