PatchSiren

hexpm CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW hexpm CVE published 2026-08-24

CVE-2026-75554

The CVE-2026-75554 vulnerability in hexpm's OAuth token refresh grant allows a user removed from an organization to keep reading its private packages due to insufficient session expiration. This issue arises because the refresh grant re-derives a new token from stored granted scopes, reproducing the organization scope without revisiting membership. The affected product is hex.pm, which is used for managin [truncated]

HIGH hexpm CVE published 2026-08-24

CVE-2026-75542

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-24T21:17:47.373Z and has not been modified since then. CVE-2026-75542 is an Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm. An API key holding the repositories permission can read another organization's private packages. The vulnerability arises because validate_sco [truncated]

HIGH hexpm CVE published 2026-03-13

CVE-2026-23940

CVE-2026-23940 is an Uncontrolled Resource Consumption vulnerability in hexpm. Publishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball, potentially terminating the affected application instance and resulting in a denial of service for package publishing and other package-processing functionality. This issue affects hexpm before version 495f01607d [truncated]