Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hx9w-f2w9-9g96

Опубликовано: 01 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2

Описание

hex_core has Unsafe Deserialization of Erlang Terms

Impact

The Hex client (hex_core) deserializes Erlang terms received from the Hex API using binary_to_term/1 without sufficient restrictions.

If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution.

Patches

Workarounds

Ensure that the Hex API URL (HEX_API_URL) points only to trusted endpoints. There is no client-side workaround that fully mitigates this issue without applying the patch.

Resources

Пакеты

Наименование

hex_core

Затронутые версииВерсия исправления

< 0.12.1

0.12.1

EPSS

Процентиль: 14%
0.00046
Низкий

2 Low

CVSS4

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4. This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.

CVSS3: 7.5
nvd
около 1 месяца назад

Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4. This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.

CVSS3: 7.5
debian
около 1 месяца назад

Uncontrolled Resource Consumption, Deserialization of Untrusted Data v ...

EPSS

Процентиль: 14%
0.00046
Низкий

2 Low

CVSS4

Дефекты

CWE-400