PatchSiren

hexpm CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH hexpm CVE published 2026-03-13

CVE-2026-23940

CVE-2026-23940 is an Uncontrolled Resource Consumption vulnerability in hexpm. Publishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball, potentially terminating the affected application instance and resulting in a denial of service for package publishing and other package-processing functionality. This issue affects hexpm before version 495f01607d [truncated]