Hex
Hexpm · 2 CVEs
CVE-2026-32148
HIGH
Lockfile checksums not verified in Hex allows dependency integrity bypass
Apr 30, 2026
CVE-2026-21619
LOW
Unsafe Deserialization of Erlang Terms in hex_core
Feb 27, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-32148 | Lockfile checksums not verified in Hex allows dependency integrity bypass | HIGH | 0.26% | Apr 30, 2026 |
| CVE-2026-21619 | Unsafe Deserialization of Erlang Terms in hex_core | LOW | 0.60% | Feb 27, 2026 |
Showing 1 to 2 of 2 CVEs