Back

HIGH

Denial of Service via Oversized Package Upload

Published Mar 13, 2026

Description

Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation.

Publishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball. This can terminate the affected application instance and result in a denial of service for package publishing and potentially other package-processing functionality.

This issue affects hex.pm: before 2026-03-10.

Affected products

Remediation

Vendor solution

* Prevent large package uploads by enforcing upload size limits at the reverse proxy or load balancer level.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner EEF
Published Mar 13, 2026
Updated Sep 8, 2026
Reserved Jan 19, 2026
CISA Vulnrichment
Updated Mar 16, 2026
NVD
Status Modified
Modified Sep 8, 2026
Red Hat
Severity n/a
Public date n/a