---
id: CVE-2026-23940
title: >-
  Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows
  Excessive Allocation.


  Publishing an oversized package can cause Hex.pm to run out of memory while
  extracting the uploaded package tarball
summary: >-
  Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows
  Excessive Allocation.


  Publishing an oversized package can cause Hex.pm to run out of memory while
  extracting the uploaded package tarball. This can terminate th…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
vendor: hex
product: hexpm
affected:
  - hexpm < 2026-03-09
patched:
  - hexpm 2026-03-09
published: '2026-03-13'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T14:17:21.340'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-23940'
references:
  - url: 'https://cna.erlef.org/cves/CVE-2026-23940.html'
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
  - url: >-
      https://github.com/hexpm/hexpm/commit/495f01607d3eae4aed7ad09b2f54f31ec7a7df01
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
  - url: >-
      https://github.com/hexpm/hexpm/commit/82911daf5f8fb2ab44f298e3ba22b90bc1ae3746
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
  - url: 'https://github.com/hexpm/hexpm/security/advisories/GHSA-jp8w-gxf6-8hcr'
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
  - url: 'https://osv.dev/vulnerability/EEF-CVE-2026-23940'
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-03-16T17:06:18.779960Z'
epss: 0.0044
epssPercentile: 0.35494
ingestedAt: '2026-07-24T15:30:58.146Z'
---

## Overview

Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation.

Publishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball. This can terminate the affected application instance and result in a denial of service for package publishing and potentially other package-processing functionality.

This issue affects hex.pm: before 2026-03-10.

## Affected

- `hexpm < 2026-03-09`

## Remediation

Upgrade past the affected range:

- `hexpm 2026-03-09`
