CVE-2026-32148
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 2 assertions
{"cpes":["cpe:2.3:a:hexpm:hex:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.Hex.RemoteConverger'"],"packageName":"hex","packageURL":"pkg:otp/hex?repository_url=https:%2F%2Fgithub.com%2Fhexpm%2Fhex&vcs_url=git%20https:%2F%2Fgithub.com%2Fhexpm%2Fhex.git","product":"hex","programFiles":["lib/hex/remote_converger.ex"],"programRoutines":[{"name":"'Elixir.Hex.RemoteConverger':verify_resolved/2"}],"repo":"https://github.com/hexpm/hex","vendor":"hexpm","versions":[{"lessThan":"2.4.2","status":"affected","version":"0.16.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d8db755b9a6f760740932e0ae43c3087bdc2d3fe9314f776e0f083d47b6cc150 · sha256:c6e14d2ba6cf5aa0… · /containers/cna/affected/0
{"collectionURL":"https://github.com","cpes":["cpe:2.3:a:hexpm:hex:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.Hex.RemoteConverger'"],"packageName":"hexpm/hex","packageURL":"pkg:github/hexpm/hex","product":"hex","programFiles":["lib/hex/remote_converger.ex"],"programRoutines":[{"name":"'Elixir.Hex.RemoteConverger':verify_resolved/2"}],"repo":"https://github.com/hexpm/hex.git","vendor":"hexpm","versions":[{"lessThan":"d7528c8199a1144511508bf3a6460026a5a14c8e","status":"affected","version":"e01576f28c64af9fae6eb17e2dad30f6efcb303c","versionType":"git"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d8db755b9a6f760740932e0ae43c3087bdc2d3fe9314f776e0f083d47b6cc150 · sha256:c6e14d2ba6cf5aa0… · /containers/cna/affected/1
cwe · 2 assertions
{"cweId":"CWE-354","description":"CWE-354 Improper Validation of Integrity Check Value","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d8db755b9a6f760740932e0ae43c3087bdc2d3fe9314f776e0f083d47b6cc150 · sha256:c6e14d2ba6cf5aa0… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-494","description":"CWE-494 Download of Code Without Integrity Check","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d8db755b9a6f760740932e0ae43c3087bdc2d3fe9314f776e0f083d47b6cc150 · sha256:c6e14d2ba6cf5aa0… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
2 source assertions{"cpes":["cpe:2.3:a:hexpm:hex:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.Hex.RemoteConverger'"],"packageName":"hex","packageURL":"pkg:otp/hex?repository_url=https:%2F%2Fgithub.com%2Fhexpm%2Fhex&vcs_url=git%20https:%2F%2Fgithub.com%2Fhexpm%2Fhex.git","product":"hex","programFiles":["lib/hex/remote_converger.ex"],"programRoutines":[{"name":"'Elixir.Hex.RemoteConverger':verify_resolved/2"}],"repo":"https://github.com/hexpm/hex","vendor":"hexpm","versions":[{"lessThan":"2.4.2","status":"affected","version":"0.16.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d8db755b9a6f760740932e0ae43c3087bdc2d3fe9314f776e0f083d47b6cc150 · sha256:c6e14d2ba6cf5aa0… · /containers/cna/affected/0
{"collectionURL":"https://github.com","cpes":["cpe:2.3:a:hexpm:hex:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["'Elixir.Hex.RemoteConverger'"],"packageName":"hexpm/hex","packageURL":"pkg:github/hexpm/hex","product":"hex","programFiles":["lib/hex/remote_converger.ex"],"programRoutines":[{"name":"'Elixir.Hex.RemoteConverger':verify_resolved/2"}],"repo":"https://github.com/hexpm/hex.git","vendor":"hexpm","versions":[{"lessThan":"d7528c8199a1144511508bf3a6460026a5a14c8e","status":"affected","version":"e01576f28c64af9fae6eb17e2dad30f6efcb303c","versionType":"git"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d8db755b9a6f760740932e0ae43c3087bdc2d3fe9314f776e0f083d47b6cc150 · sha256:c6e14d2ba6cf5aa0… · /containers/cna/affected/1
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":8.9,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpa…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d8db755b9a6f760740932e0ae43c3087bdc2d3fe9314f776e0f083d47b6cc150 · sha256:c6e14d2ba6cf5aa0… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-354","description":"CWE-354 Improper Validation of Integrity Check Value","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d8db755b9a6f760740932e0ae43c3087bdc2d3fe9314f776e0f083d47b6cc150 · sha256:c6e14d2ba6cf5aa0… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-494","description":"CWE-494 Download of Code Without Integrity Check","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d8db755b9a6f760740932e0ae43c3087bdc2d3fe9314f776e0f083d47b6cc150 · sha256:c6e14d2ba6cf5aa0… · /containers/cna/problemTypes/1/descriptions/0
Source references
5 source assertions{"tags":["related"],"url":"https://cna.erlef.org/cves/CVE-2026-32148.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d8db755b9a6f760740932e0ae43c3087bdc2d3fe9314f776e0f083d47b6cc150 · sha256:c6e14d2ba6cf5aa0… · /containers/cna/references/1
{"tags":["patch"],"url":"https://github.com/hexpm/hex/commit/d7528c8199a1144511508bf3a6460026a5a14c8e"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d8db755b9a6f760740932e0ae43c3087bdc2d3fe9314f776e0f083d47b6cc150 · sha256:c6e14d2ba6cf5aa0… · /containers/cna/references/3
{"tags":["exploit"],"url":"https://github.com/hexpm/hex/security/advisories/GHSA-hmv9-4mfr-m92v"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d8db755b9a6f760740932e0ae43c3087bdc2d3fe9314f776e0f083d47b6cc150 · sha256:c6e14d2ba6cf5aa0… · /containers/adp/0/references/0
{"tags":["vendor-advisory","related"],"url":"https://github.com/hexpm/hex/security/advisories/GHSA-hmv9-4mfr-m92v"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d8db755b9a6f760740932e0ae43c3087bdc2d3fe9314f776e0f083d47b6cc150 · sha256:c6e14d2ba6cf5aa0… · /containers/cna/references/0
{"tags":["related"],"url":"https://osv.dev/vulnerability/EEF-CVE-2026-32148"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d8db755b9a6f760740932e0ae43c3087bdc2d3fe9314f776e0f083d47b6cc150 · sha256:c6e14d2ba6cf5aa0… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.