PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23940 hexpm CVE debrief

CVE-2026-23940 is an Uncontrolled Resource Consumption vulnerability in hexpm. Publishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball, potentially terminating the affected application instance and resulting in a denial of service for package publishing and other package-processing functionality. This issue affects hexpm before version 495f01607d3eae4aed7ad09b2f54f31ec7a7df01 and hex.pm before 2026-03-10. The vulnerability has a high CVSS score of 7.1 and is considered a high priority due to potential for denial of service attacks.

Vendor
hexpm
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-13
Original CVE updated
2026-07-24
Advisory published
2026-03-13
Advisory updated
2026-07-24

Who should care

Users of hexpm before version 495f01607d3eae4aed7ad09b2f54f31ec7a7df01 and hex.pm before 2026-03-10 should apply patches or mitigations to prevent denial of service attacks. This includes operators, platform administrators, vulnerability management teams, and security teams responsible for maintaining and securing affected systems.

Technical summary

CVE-2026-23940 is an Uncontrolled Resource Consumption vulnerability in hexpm. Publishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball, potentially terminating the affected application instance and resulting in a denial of service for package publishing and other package-processing functionality. The vulnerability affects hexpm before version 495f01607d3eae4aed7ad09b2f54f31ec7a7df01 and hex.pm before 2026-03-10. Users of affected versions should apply patches or mitigations to prevent denial of service attacks.

Defensive priority

High priority due to potential for denial of service attacks.

Recommended defensive actions

  • Apply patches or updates to hexpm and hex.pm to prevent denial of service attacks.
  • Implement compensating controls to monitor and limit resource consumption.
  • Conduct inventory checks to identify affected systems and prioritize patching.
  • Monitor for suspicious activity and exception tracking.
  • Review and update incident response plans to address potential denial of service attacks.
  • Verify affected systems and apply patches or mitigations accordingly.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability and affected versions. The vendor has released patches and mitigations to address the issue. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability. Defenders should verify affected systems and apply patches or mitigations accordingly. Additional information from other sources may be necessary to fully understand the vulnerability.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-13T19:54:14.640Z and has not been modified since then.