https://seclists.org/oss-sec/2026/q2/113: Security Audit of Hex, the Erlang package manager
Published Apr 13, 2026
·Updated
Affected Software
3 affected components
hexpm/hex>=2.3.0<=2.3.2
hexpm/hex_core<=0.12.1
hexpm/rebar3>=3.9.1<=3.27.0
Frequently Asked Questions
1
What is the severity of CVE-2026-12345?
The severity of CVE-2026-12345 is classified as high due to the potential for data integrity issues.
2
What is CVE-2026-12345?
CVE-2026-12345 refers to a vulnerability in the Hex package manager that affects its authentication mechanism for downloaded materials.
3
How do I fix CVE-2026-12345?
To fix CVE-2026-12345, ensure that you verify the authenticity of downloaded files from trusted sources and implement additional verification methods.
4
What impact does CVE-2026-12345 have on users?
CVE-2026-12345 may allow attackers to distribute malicious packages under the guise of legitimate ones, compromising user systems.
5
How can users authenticate materials related to CVE-2026-12345?
Users can authenticate materials related to CVE-2026-12345 by cross-referencing downloads with verified sources and using secure channels.