https://seclists.org/oss-sec/2026/q2/109: Security Audit of Hex, the Erlang package manager
Published Apr 12, 2026
·Updated
Affected Software
3 affected components
hexpm/hex>=2.3.0<=2.3.2
hexpm/hex_core<=0.12.1
hexpm/rebar3>=3.9.1<=3.27.0
Frequently Asked Questions
1
What vulnerabilities were identified in HEXPM-2026-04-12?
The security audit revealed several vulnerabilities related to dependency management and package distribution in the Hex package manager.
2
What is the severity level of HEXPM-2026-04-12 vulnerabilities?
The identified vulnerabilities in HEXPM-2026-04-12 are classified as high severity due to their potential impact on the integrity of package installations.
3
How do I update Hex to fix HEXPM-2026-04-12 vulnerabilities?
You can fix the vulnerabilities in HEXPM-2026-04-12 by updating your Hex installation to the latest version using the command 'mix local.hex'.
4
Are there any known exploits for HEXPM-2026-04-12?
As of now, there are no publicly disclosed exploits specifically targeting the vulnerabilities identified in HEXPM-2026-04-12.
5
What should developers do to mitigate the risks of HEXPM-2026-04-12?
Developers should review their package dependencies and implement the latest security patches as recommended in the security audit results for HEXPM-2026-04-12.