PT-2026-51266 · Mageia · Erlang-Hex Core+1
Published
2026-06-11
·
Updated
2026-06-11
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Uncontrolled Resource Consumption, Deserialization of Untrusted Data
vulnerability in hexpm hex core (hex api modules), hexpm hex
(mix hex api modules), erlang rebar3 (r3 hex api modules) allows Object
Injection, Excessive Allocation. This vulnerability is associated with
program files src/hex api.erl, src/mix hex api.erl,
apps/rebar/src/vendored/r3 hex api.erl and program routines
hex core:request/4, mix hex api:request/4, r3 hex api:request/4. This
issue affects hex core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before
2.3.2; rebar3: from 3.9.1 before 3.27.0.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Erlang-Hex Core
Erlang-Rebar3