<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:25:57 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15273</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15273</link>
      <description>bdu:2026-15273</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15273</guid>
    </item>
    <item>
      <title>EUVD-2026-322088</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322088</link>
      <description>EUVD-2026-322088</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322088</guid>
    </item>
    <item>
      <title>fkie_cve-2026-21619</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-21619</link>
      <description>&lt;p&gt;Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4.&lt;/p&gt;
&lt;p&gt;This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4.&lt;/p&gt;
&lt;p&gt;This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-21619</guid>
    </item>
    <item>
      <title>GHSA-hx9w-f2w9-9g96 — hex_core has Unsafe Deserialization of Erlang Terms</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hx9w-f2w9-9g96</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: hex_core&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The Hex client (`hex_core`) deserializes Erlang terms received from the Hex API using `binary_to_term/1` without sufficient restrictions.&lt;/p&gt;
&lt;p&gt;If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as **atom table exhaustion**, leading to a VM crash. No released versions are known to allow remote code execution.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;* https://github.com/hexpm/hex_core/commit/cdf726095bca85ad2549d146df1e831ae93c2b13
* https://github.com/hexpm/hex/commit/636739f3322514e9303ca335fb630696fcbb3c95
* https://github.com/erlang/rebar3/commit/1d4478f527e373de0b225951e53115450e0d9b9d&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Ensure that the Hex API URL (`HEX_API_URL`) points only to trusted endpoints. There is no client-side workaround that fully mitigates this issue without applying the patch.&lt;/p&gt;
&lt;p&gt;### Resources&lt;/p&gt;
&lt;p&gt;* hex_core Module: https://github.com/hexpm/hex_core/blob/main/src/hex_api.erl
* Hex Vendored Module: https://github.com/hexpm/hex/blob/main/src/mix_hex_api.erl
* Rebar3 Vendored Module: https://github.com/erlang/rebar3/blob/main/apps/rebar/src/vendored/r3_hex_api.erl
* hex_core Patch: https://github.com/hexpm/hex_core/commit/cdf726095bca85ad2549d146df1e831ae93c2b13
* Hex Vendored Patch: https://github.com/hexpm/hex/commit/636739f3322514e9303ca335fb630696fcbb3c95
* Rebar3 Vendored Patch: https://github.com/erlang/rebar3/commit/1d4478f527e373de0b225951e53115450e0d9b9d&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: hex_core&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The Hex client (`hex_core`) deserializes Erlang terms received from the Hex API using `binary_to_term/1` without sufficient restrictions.&lt;/p&gt;
&lt;p&gt;If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as **atom table exhaustion**, leading to a VM crash. No released versions are known to allow remote code execution.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;* https://github.com/hexpm/hex_core/commit/cdf726095bca85ad2549d146df1e831ae93c2b13
* https://github.com/hexpm/hex/commit/636739f3322514e9303ca335fb630696fcbb3c95
* https://github.com/erlang/rebar3/commit/1d4478f527e373de0b225951e53115450e0d9b9d&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Ensure that the Hex API URL (`HEX_API_URL`) points only to trusted endpoints. There is no client-side workaround that fully mitigates this issue without applying the patch.&lt;/p&gt;
&lt;p&gt;### Resources&lt;/p&gt;
&lt;p&gt;* hex_core Module: https://github.com/hexpm/hex_core/blob/main/src/hex_api.erl
* Hex Vendored Module: https://github.com/hexpm/hex/blob/main/src/mix_hex_api.erl
* Rebar3 Vendored Module: https://github.com/erlang/rebar3/blob/main/apps/rebar/src/vendored/r3_hex_api.erl
* hex_core Patch: https://github.com/hexpm/hex_core/commit/cdf726095bca85ad2549d146df1e831ae93c2b13
* Hex Vendored Patch: https://github.com/hexpm/hex/commit/636739f3322514e9303ca335fb630696fcbb3c95
* Rebar3 Vendored Patch: https://github.com/erlang/rebar3/commit/1d4478f527e373de0b225951e53115450e0d9b9d&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hx9w-f2w9-9g96</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-21619</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-21619</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: rebar3, Ubuntu:24.04:LTS: rebar3, Ubuntu:25.10: rebar3, Ubuntu:26.04:LTS: rebar3&lt;/p&gt;
&lt;p&gt;Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4. This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: rebar3, Ubuntu:24.04:LTS: rebar3, Ubuntu:25.10: rebar3, Ubuntu:26.04:LTS: rebar3&lt;/p&gt;
&lt;p&gt;Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4. This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-21619</guid>
    </item>
  </channel>
</rss>
