Uncontrolled Resource Consumption in Hex.pm Affects Hexpm Packages
CVE-2026-23940

7.1HIGH

Key Information:

Vendor

Hexpm

Vendor
CVE Published:
13 March 2026

What is CVE-2026-23940?

An uncontrolled resource consumption vulnerability in Hex.pm allows for excessive memory allocation during the extraction of overly large package tarballs. If a user publishes a package that exceeds memory limits, it can lead to application instance termination, triggering denial of service for both package publishing and processing functionalities. This issue poses risks for developers relying on the Hex.pm platform for package management, and it’s advisable to apply the necessary patches to prevent potential impacts.

Affected Version(s)

hex.pm 0 < 2026-03-10

hexpm 0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joud Zakharia / zentrust partners GmbH
Eric Meadows-Jönsson / Hex.pm
.