
CVE-2026-23940 Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation. Publishing an oversized package can cause http://Hex.pm to run out of memor… https://www.cve.org/CVERecord?id=CVE-2026-23940
Post summary
The entry announces CVE‑2026‑23940, describing it as an uncontrolled resource consumption flaw in Hex.pm that can lead to memory exhaustion when an oversized package is published.
