Current section
3 Advisories
Jump to
Current section
3 Advisories
hex_core has Unsafe Deserialization of Erlang Terms
Affected Versions
References
- https://osv.dev/vulnerability/EEF-CVE-2026-21619
- https://github.com/hexpm/hex/commit/636739f3322514e9303ca335fb630696fcbb3c95
- https://github.com/hexpm/hex_core/commit/cdf726095bca85ad2549d146df1e831ae93c2b13
- https://cna.erlef.org/cves/CVE-2026-21619.html
- https://github.com/hexpm/hex_core
- https://github.com/hexpm/hex_core/security/advisories/GHSA-hx9w-f2w9-9g96
- https://nvd.nist.gov/vuln/detail/CVE-2026-21619
- https://github.com/erlang/rebar3/commit/1d4478f527e373de0b225951e53115450e0d9b9d
Unsafe Deserialization of Erlang Terms in hex_core
Affected Versions
References
- https://github.com/hexpm/hex_core/security/advisories/GHSA-hx9w-f2w9-9g96
- https://cna.erlef.org/cves/CVE-2026-21619.html
- https://github.com/hexpm/hex_core/commit/cdf726095bca85ad2549d146df1e831ae93c2b13
- https://github.com/hexpm/hex/commit/636739f3322514e9303ca335fb630696fcbb3c95
- https://github.com/erlang/rebar3/commit/1d4478f527e373de0b225951e53115450e0d9b9d
- https://hex.pm/packages/hex_core
Hex authenticity of signed packages not validated
Affected Versions
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
11 011
yesterday
19 113
last 7 days
118 429
all time
49 223 003