Uncontrolled Resource Consumption in Hex.pm Affects Hexpm Packages
CVE-2026-23940
7.1HIGH
What is CVE-2026-23940?
An uncontrolled resource consumption vulnerability in Hex.pm allows for excessive memory allocation during the extraction of overly large package tarballs. If a user publishes a package that exceeds memory limits, it can lead to application instance termination, triggering denial of service for both package publishing and processing functionalities. This issue poses risks for developers relying on the Hex.pm platform for package management, and it’s advisable to apply the necessary patches to prevent potential impacts.
Affected Version(s)
hex.pm 0 < 2026-03-10
hexpm 0
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Joud Zakharia / zentrust partners GmbH
Eric Meadows-Jönsson / Hex.pm
