CVE-2026-75542 | hexpm prior 2026-08-24 OAuth token endpoint oauth_controller.ex validate_scopes_against_key improper authorization
A vulnerability identified as problematic has been detected in hexpm. Affected by this vulnerability is the function validate_scopes_against_key of the file lib/hexpm_web/controllers/api/oauth_controller.ex of the component OAuth token endpoint. The manipulation leads to improper authorization.
This vulnerability is listed as CVE-2026-75542. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More