The CVE-2026-75554 vulnerability in hexpm's OAuth token refresh grant allows a user removed from an organization to keep reading its private packages due to insufficient session expiration. This issue arises because the refresh grant re-derives a new token from stored granted scopes, reproducing the organization scope without revisiting membership. The affected product is hex.pm, which is used for managin [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-24T21:17:47.373Z and has not been modified since then. CVE-2026-75542 is an Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm. An API key holding the repositories permission can read another organization's private packages. The vulnerability arises because validate_sco [truncated]
CVE-2026-23940 is an Uncontrolled Resource Consumption vulnerability in hexpm. Publishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball, potentially terminating the affected application instance and resulting in a denial of service for package publishing and other package-processing functionality. This issue affects hexpm before version 495f01607d [truncated]