HIGH
Denial of Service via Oversized Package Upload
Published Mar 13, 2026
7.1
HIGHCVSS 4.0
EPSS 0.44%
Description
Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation.
Publishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball. This can terminate the affected application instance and result in a denial of service for package publishing and potentially other package-processing functionality.
This issue affects hex.pm: before 2026-03-10.
Affected products
-
- Version 0StatusaffectedConstraints<2026-03-10
- Version
-
- Version StatusaffectedConstraints
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
* Prevent large package uploads by enforcing upload size limits at the reverse proxy or load balancer level.
Weaknesses (1)
References (5)
- https://cna.erlef.org/cves/CVE-2026-23940.html related
- https://github.com/hexpm/hexpm/commit/495f01607d3eae4aed7ad09b2f54f31ec7a7df01 patch
- https://github.com/hexpm/hexpm/commit/82911daf5f8fb2ab44f298e3ba22b90bc1ae3746 related
- https://github.com/hexpm/hexpm/security/advisories/GHSA-jp8w-gxf6-8hcr vendor-advisoryrelatedMitigationVendor Advisory
- https://osv.dev/vulnerability/EEF-CVE-2026-23940 related
| Link | Providers | Tags |
|---|---|---|
| https://cna.erlef.org/cves/CVE-2026-23940.html | related | |
| https://github.com/hexpm/hexpm/commit/495f01607d3eae4aed7ad09b2f54f31ec7a7df01 | patch | |
| https://github.com/hexpm/hexpm/commit/82911daf5f8fb2ab44f298e3ba22b90bc1ae3746 | related | |
| https://github.com/hexpm/hexpm/security/advisories/GHSA-jp8w-gxf6-8hcr | vendor-advisoryrelatedMitigationVendor Advisory | |
| https://osv.dev/vulnerability/EEF-CVE-2026-23940 | related |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner EEF
Published Mar 13, 2026
Updated Sep 8, 2026
Reserved Jan 19, 2026
Link CVE-2026-23940
CISA Vulnrichment
Updated Mar 16, 2026