
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21619 is an unsafe deserialization of Erlang terms vulnerability affecting the Hex package manager ecosystem, specifically hexpm/hex_core, hexpm/hex, and erlang/rebar3. The flaw exists in the request/4 routines (hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4) within the files src/hex_api.erl, src/mix_hex_api.erl, and apps/rebar/src/vendored/r3_hex_api.erl. Affected versions are hex_core 0.1.0 through <0.12.1, hex 2.3.0 through <2.3.2, and rebar3 3.9.1 through <3.27.0. It was published on February 27, 2026, with a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 2.0 (Low) (Github Advisory, GHSA Advisory).
The root cause is the use of Erlang's binary_to_term/1 without the safe option or term validation when deserializing HTTP response bodies from the Hex API (CWE-502: Deserialization of Untrusted Data; CWE-400: Uncontrolled Resource Consumption). When the Hex API returns a response with an Erlang binary content type, the client blindly deserializes the body, allowing a malicious or compromised API endpoint to inject crafted Erlang terms. This enables atom table exhaustion — since Erlang atoms are never garbage collected, flooding the VM with new atoms causes memory exhaustion and a VM crash (denial of service). The fix introduced a safe_binary_to_term wrapper that uses binary_to_term(Binary, [safe]) to prevent new atom creation and validates deserialized terms to reject executable types such as functions and ports (GHSA Advisory, hex_core patch).
Successful exploitation results in a denial-of-service condition through Erlang VM crash caused by atom table exhaustion or excessive memory allocation. There is no known impact to confidentiality or integrity — no released versions are known to allow remote code execution. The vulnerability affects the availability of package management operations for developers and CI/CD pipelines using hex_core, the Elixir hex mix task, or rebar3 for Erlang dependency management (Github Advisory, GHSA Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). Exploitation requires the attacker to control or intercept the HTTP response from the Hex API endpoint (e.g., via a man-in-the-middle attack, a rogue mirror, or a misconfigured HEX_API_URL), and also requires a developer or automated process to trigger a package operation. The EPSS score is approximately 0.068% (21st percentile), indicating low near-term exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Detection plugins are available via Qualys (ID 288225) and Nessus (ID 302196) (Github Advisory).
HEX_API_URL environment variable pointing to an attacker-controlled server.mix deps.get, rebar3 get-deps) that causes the vulnerable client to make an HTTP request to the Hex API.application/vnd.hex+erlang) and a body containing a crafted Erlang binary term — for example, a large number of unique atoms encoded via term_to_binary/1 — designed to exhaust the Erlang atom table.request/4 function calls binary_to_term/1 on the response body without restrictions, deserializing the malicious term and flooding the atom table.Content-Type: application/vnd.hex+erlang from non-official or misconfigured Hex API endpoints; DNS queries or connections to unknown hosts when HEX_API_URL is set to a non-default value.erl_crash.dump files generated during or after package manager operations; error messages referencing binary_to_term or atom table limits in build/CI logs.mix, rebar3, or related Erlang/Elixir build processes during dependency resolution; abnormally high memory consumption by the Erlang VM process during package operations.HEX_API_URL environment variable set to a non-standard or unexpected endpoint in build environments.Update all affected packages to their patched versions: hex_core to 0.12.1 or later, hex (mix task) to 2.3.2 or later, and rebar3 to 3.27.0 or later (Github Advisory). As a workaround prior to patching, ensure the HEX_API_URL environment variable points only to the official, trusted Hex API endpoint; the advisory notes there is no client-side workaround that fully mitigates the issue without applying the patch. Additionally, restrict network access from build environments to only trusted package repository sources to reduce exposure to malicious API responses (GHSA Advisory).
The vulnerability was discovered by researcher realcorvus and remediated by maennchen (hex_core maintainer). The Hex.pm team published a security audit blog post referencing the issue (Hex Security Audit). The issue was also discussed on the oss-security mailing list and received coverage from Linux security advisories for Fedora and CentOS packages. Community reaction has been measured given the low CVSS v4 score and limited exploitation potential, with the primary concern being supply-chain risk in CI/CD environments.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."