PatchSiren

gleam-lang CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH gleam-lang CVE published 2026-07-29

CVE-2026-59247

A vulnerability in Gleam's dependency resolution process allows an adversary in the middle to substitute forged Hex package contents, leading to loss of integrity of the downloaded package contents. This issue affects Gleam versions from 0.18.0 before 1.18.0 and can be mitigated by verifying the integrity of downloaded packages, using secure connections to the Hex repository, and updating Gleam to version [truncated]