PT-2026-96829 · Hexpm · Hex.Pm

·

CVE-2026-86698

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions hex.pm versions 2025-10-10 through 2026-09-21
Description An insufficient session expiration issue in OAuth token issuance allows users whose organization membership or session has ended to continue reading private packages and documentation tarballs. This occurs because the generate refresh token/4 function in lib/hexpm/oauth/jwt.ex signs refresh tokens with the same iss, aud, and scope claims as access tokens, including the repository:<org> scope. The CDN service serving private repositories authorizes access based on the scope claim after verifying the signature and time claims, without performing a database lookup. Consequently, the CDN cannot distinguish between access tokens and refresh tokens. While access tokens expire in 30 minutes, refresh tokens remain valid for 30 days, extending unauthorized read-only access to organizations the account belonged to at the time the token was granted.
Recommendations Update hex.pm to a version released on or after 2026-09-22.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86698
GHSA-VMW7-7G2W-GW2F

Affected Products

Hex.Pm