{"id":"CVE-2019-1000013","aliases":["GHSA-q3cc-rr2c-87r6"],"url":"https://o3.security/vulnerability/CVE-2019-1000013","summary":"Hex authenticity of signed packages not validated","details":"Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via victim fetches packages from malicious/compromised mirror. This vulnerability appears to have been fixed in 0.4.0.","published":"2019-02-04T21:29:01.143Z","modified":"2026-07-08T20:15:19.670171Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Hex","name":"hex_core","fixedVersion":"0.4.0"}],"fix":{"url":"https://github.com/hexpm/hex_core/pull/48","label":"hexpm/hex_core#48"},"references":[{"type":"FIX","url":"https://github.com/hexpm/hex_core/pull/48"},{"type":"FIX","url":"https://github.com/hexpm/hex_core/pull/51"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-1000013"},{"type":"PACKAGE","url":"https://github.com/hexpm/hex_core"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T20:15:19.670171Z"}}