hexpm has 2 CVEs on record. 1 was published in the last 90 days. The median CVSS is 4.6 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.6
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-23939Medium· 6.9Path Traversal in Local File Store Backend38CVE-2026-86698Low· 2.3Insufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organization membership or session has ended to keep reading the organization's private packages and their documentation tarballs vi…25
hexpm vulnerabilities
CVEs affecting hexpm, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-86698Low· 2.3PoCInsufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organization membership or session has ended to keep reading the organization's private packages and their documentation tarballs vi…
Insufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organization membership or session has ended to keep reading the organization's private packages and their documentation tarballs vi…
▾ Twilighthexpm · hex.pmvia NVD
CVE-2026-23939Medium· 6.9Path Traversal in Local File Store Backend
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Store.Local' module) allows Relative Path Traversal. This vulnerability is associated with program files lib…
▾ Sunlithexpm · hexpm/hexpmEPSS 0.41%via CVEORG