<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:35:46.417700+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-15273</id>
    <title>bdu:2026-15273</title>
    <updated>2026-10-02T15:35:46.533777+00:00</updated>
    <content>bdu:2026-15273</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-15273"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322088</id>
    <title>EUVD-2026-322088</title>
    <updated>2026-10-02T15:35:46.533821+00:00</updated>
    <content>EUVD-2026-322088</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-21619</id>
    <title>fkie_cve-2026-21619</title>
    <updated>2026-10-02T15:35:46.533842+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4.</p>
<p>This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-21619"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hx9w-f2w9-9g96</id>
    <title>GHSA-hx9w-f2w9-9g96 — hex_core has Unsafe Deserialization of Erlang Terms</title>
    <updated>2026-10-02T15:35:46.533894+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Hex: hex_core</p>
<p>### Impact</p>
<p>The Hex client (`hex_core`) deserializes Erlang terms received from the Hex API using `binary_to_term/1` without sufficient restrictions.</p>
<p>If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as **atom table exhaustion**, leading to a VM crash. No released versions are known to allow remote code execution.</p>
<p>### Patches</p>
<p>* https://github.com/hexpm/hex_core/commit/cdf726095bca85ad2549d146df1e831ae93c2b13
* https://github.com/hexpm/hex/commit/636739f3322514e9303ca335fb630696fcbb3c95
* https://github.com/erlang/rebar3/commit/1d4478f527e373de0b225951e53115450e0d9b9d</p>
<p>### Workarounds</p>
<p>Ensure that the Hex API URL (`HEX_API_URL`) points only to trusted endpoints. There is no client-side workaround that fully mitigates this issue without applying the patch.</p>
<p>### Resources</p>
<p>* hex_core Module: https://github.com/hexpm/hex_core/blob/main/src/hex_api.erl
* Hex Vendored Module: https://github.com/hexpm/hex/blob/main/src/mix_hex_api.erl
* Rebar3 Vendored Module: https://github.com/erlang/rebar3/blob/main/apps/rebar/src/vendored/r3_hex_api.erl
* hex_core Patch: https://github.com/hexpm/hex_core/commit/cdf726095bca85ad2549d146df1e831ae93c2b13
* Hex Vendored Patch: https://github.com/hexpm/hex/commit/636739f3322514e9303ca335fb630696fcbb3c95
* Rebar3 Vendored Patch: https://github.com/erlang/rebar3/commit/1d4478f527e373de0b225951e53115450e0d9b9d</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hx9w-f2w9-9g96"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-21619</id>
    <title>UBUNTU-CVE-2026-21619</title>
    <updated>2026-10-02T15:35:46.533967+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: rebar3, Ubuntu:24.04:LTS: rebar3, Ubuntu:25.10: rebar3, Ubuntu:26.04:LTS: rebar3</p>
<p>Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4. This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-21619"/>
  </entry>
</feed>
