hex_core
Reference implementation of Hex specifications
Activity
- Latest release
- 1mo ago
- Total releases
- 44
- Cadence
- ~18 days
- Last 12 months
- 12
Details
- License
- Apache-2.0
- First release
- Aug 08, 2018
| Version | Released | |
|---|---|---|
0.19.0
minor
| ||
0.18.0
minor
| ||
0.17.0
minor
| ||
0.16.1
patch
| ||
0.16.0
minor
| ||
0.15.0
minor
| ||
0.14.1
patch
| ||
0.14.0
minor
| ||
0.13.0
minor
| ||
0.12.2
patch
| ||
0.12.1
patch
| ||
0.12.0
minor
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.11.0
minor
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.10.3
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.10.2
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.10.1
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.10.0
minor
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.9.0
minor
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.8.4
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.8.3
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.8.2
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.8.1
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.8.0
minor
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.7.1
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.7.0
minor
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.6.10
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.6.9
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.6.8
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.6.7
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.6.6
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.6.5
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.6.4
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.6.3
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.6.2
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.6.1
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.5.1
patch
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.6.0
minor
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev | ||
0.3.0
minor
2 CVEs
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev
CVE-2019-1000013
GHSA-q3cc-rr2c-87r6
May 13, 2022
Hex authenticity of signed packages not validated
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via victim fetches packages from malicious/compromised mirror. This vulnerability appears to have been fixed in 0.4.0. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.3.0
Fixed in
0.4.0
References Updated Dec 10, 2025 · Source: OSV.dev | ||
0.2.1
patch
2 CVEs
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev
CVE-2019-1000013
GHSA-q3cc-rr2c-87r6
May 13, 2022
Hex authenticity of signed packages not validated
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via victim fetches packages from malicious/compromised mirror. This vulnerability appears to have been fixed in 0.4.0. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.3.0
Fixed in
0.4.0
References Updated Dec 10, 2025 · Source: OSV.dev | ||
0.2.0
minor
2 CVEs
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev
CVE-2019-1000013
GHSA-q3cc-rr2c-87r6
May 13, 2022
Hex authenticity of signed packages not validated
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via victim fetches packages from malicious/compromised mirror. This vulnerability appears to have been fixed in 0.4.0. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.3.0
Fixed in
0.4.0
References Updated Dec 10, 2025 · Source: OSV.dev | ||
0.1.1
patch
2 CVEs
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev
CVE-2019-1000013
GHSA-q3cc-rr2c-87r6
May 13, 2022
Hex authenticity of signed packages not validated
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via victim fetches packages from malicious/compromised mirror. This vulnerability appears to have been fixed in 0.4.0. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.3.0
Fixed in
0.4.0
References Updated Dec 10, 2025 · Source: OSV.dev | ||
0.1.0
initial
2 CVEs
CVE-2026-21619
GHSA-hx9w-f2w9-9g96
EEF-CVE-2026-21619
Mar 01, 2026
hex_core has Unsafe Deserialization of Erlang Terms
Low
Network
Low
Low
ImpactThe Hex client ( If an attacker can control the HTTP response body returned by the Hex API, this allows denial-of-service attacks such as atom table exhaustion, leading to a VM crash. No released versions are known to allow remote code execution. Patches
WorkaroundsEnsure that the Hex API URL ( Resources
Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
+ 21 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
Fixed in
0.12.1
References
Updated Apr 06, 2026 · Source: OSV.dev
CVE-2019-1000013
GHSA-q3cc-rr2c-87r6
May 13, 2022
Hex authenticity of signed packages not validated
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via victim fetches packages from malicious/compromised mirror. This vulnerability appears to have been fixed in 0.4.0. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.3.0
Fixed in
0.4.0
References Updated Dec 10, 2025 · Source: OSV.dev |