hexpm/hexpm vulnerabilities
CVEs whose affected-version data names the hexpm/hexpm package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-86698Low· 2.3PoCInsufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organization membership or session has ended to keep reading the organization's private packages and their documentation tarballs vi…
Insufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organization membership or session has ended to keep reading the organization's private packages and their documentation tarballs vi…
▾ Twilighthexpm · hex.pmvia NVD
CVE-2026-23939Medium· 6.9Path Traversal in Local File Store Backend
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Store.Local' module) allows Relative Path Traversal. This vulnerability is associated with program files lib…
▾ Sunlithexpm · hexpm/hexpmEPSS 0.41%via CVEORG