Bug 2443390 (CVE-2026-21619) - CVE-2026-21619 hex_core: hex_core, hex, rebar3: Denial of Service due to uncontrolled resource consumption
Summary: CVE-2026-21619 hex_core: hex_core, hex, rebar3: Denial of Service due to unco...
Keywords:
Status: NEW
Alias: CVE-2026-21619
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2443786
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-02-27 19:01 UTC by OSIDB Bzimport
Modified: 2026-03-02 11:46 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-02-27 19:01:33 UTC
Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4.

This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.


Note You need to log in before you can comment on or make changes to this bug.