PatchSiren cyber security CVE debrief
CVE-2026-23940 hexpm CVE debrief
CVE-2026-23940 is an Uncontrolled Resource Consumption vulnerability in hexpm. Publishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball, potentially terminating the affected application instance and resulting in a denial of service for package publishing and other package-processing functionality. This issue affects hexpm before version 495f01607d3eae4aed7ad09b2f54f31ec7a7df01 and hex.pm before 2026-03-10. The vulnerability has a high CVSS score of 7.1 and is considered a high priority due to potential for denial of service attacks.
- Vendor
- hexpm
- Product
- Unknown
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-13
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-03-13
- Advisory updated
- 2026-07-24
Who should care
Users of hexpm before version 495f01607d3eae4aed7ad09b2f54f31ec7a7df01 and hex.pm before 2026-03-10 should apply patches or mitigations to prevent denial of service attacks. This includes operators, platform administrators, vulnerability management teams, and security teams responsible for maintaining and securing affected systems.
Technical summary
CVE-2026-23940 is an Uncontrolled Resource Consumption vulnerability in hexpm. Publishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball, potentially terminating the affected application instance and resulting in a denial of service for package publishing and other package-processing functionality. The vulnerability affects hexpm before version 495f01607d3eae4aed7ad09b2f54f31ec7a7df01 and hex.pm before 2026-03-10. Users of affected versions should apply patches or mitigations to prevent denial of service attacks.
Defensive priority
High priority due to potential for denial of service attacks.
Recommended defensive actions
- Apply patches or updates to hexpm and hex.pm to prevent denial of service attacks.
- Implement compensating controls to monitor and limit resource consumption.
- Conduct inventory checks to identify affected systems and prioritize patching.
- Monitor for suspicious activity and exception tracking.
- Review and update incident response plans to address potential denial of service attacks.
- Verify affected systems and apply patches or mitigations accordingly.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability and affected versions. The vendor has released patches and mitigations to address the issue. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability. Defenders should verify affected systems and apply patches or mitigations accordingly. Additional information from other sources may be necessary to fully understand the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23940 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23940
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23940 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23940
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cna.erlef.org/cves/CVE-2026-23940.html
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/hexpm/hexpm/commit/495f01607d3eae4aed7ad09b2f54f31ec7a7df01
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/hexpm/hexpm/security/advisories/GHSA-jp8w-gxf6-8hcr
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Mitigation, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://osv.dev/vulnerability/EEF-CVE-2026-23940
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.