Skip to main content

Vendor/product archive

hex / hexpm CVEs

Beta · best-effort

5 CVEs tagged to hex / hexpm1 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-23940

Published Mar 13, 2026

Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation. Publishing an oversized package can cause Hex.pm to run out of memory while extra…

CVSS 7.1 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-21622

Published Mar 5, 2026

Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows Account Takeover. Password reset tokens generated via the…

CVSS 9.5 · Critical
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-21621

Published Mar 5, 2026

Incorrect Authorization vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.API.OAuthController' module) allows Privilege Escalation. An API key created with read-only permissio…

CVSS 7.0 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-23939

Published Feb 26, 2026

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Store.Local' module) allows Relative Path Traversa…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-21618

Published Jan 19, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.SharedAuthorizationView' modules)…

CVSS 8.5 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1