EEF-CVE-2026-21619
Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hexcore (hexapi modules), hexpm hex (mixhexapi modules), erlang rebar3 (r3hexapi modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hexapi.erl, src/mixhexapi.erl, apps/rebar/src/vendored/r3hexapi.erl and program routines hexcore:request/4, mixhexapi:request/4, r3hexapi:request/4.
This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/hexpm/hexcore/security/advisories/GHSA-hx9w-f2w9-9g96, https://cna.erlef.org/cves/CVE-2026-21619.html, https://github.com/hexpm/hexcore/commit/cdf726095bca85ad2549d146df1e831ae93c2b13, https://github.com/hexpm/hex/commit/636739f3322514e9303ca335fb630696fcbb3c95, https://github.com/erlang/rebar3/commit/1d4478f527e373de0b225951e53115450e0d9b9d, https://hex.pm/packages/hex_core
