hex
OSS Librariespackage-ecosystem
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting hex.
- GHSA-8jgf-23q5-x7xxex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
- CVE-2026-32148Lockfile checksums not verified in Hex allows dependency integrity bypass5.9
- GHSA-4w98-xf39-23gpLoop with Unreachable Exit Condition ('Infinite Loop') in ewe
- GHSA-9w88-79f8-m3vpPermissive List of Allowed Inputs in ewe
- CVE-2026-23940Denial of Service via Oversized Package Upload6.5
- CVE-2026-28807Path Traversal in wisp.serve_static allows arbitrary file read7.5
- CVE-2026-21619Unsafe Deserialization of Erlang Terms in hex_core
- CVE-2026-21618Cross-site scripting (XSS) in OAuth Device Authorization screen6.1
- CVE-2025-68113ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay6.5
- CVE-2025-48044Authorization bypass when bypass policy condition evaluates to true
- CVE-2025-48043Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization
- CVE-2025-48042Before action hooks may execute in certain scenarios despite a request being forbidden
- CVE-2025-4754Missing Session Revocation on Logout in ash_authentication_phoenix
- CVE-2025-3864Connection pool exhaustion in hackney
- CVE-2025-32782Ash Authentication email link auto-click account confirmation vulnerability5.3