CVE-2026-21622 describes an Insufficient Session Expiration vulnerability in hexpm/hexpm, specifically within the Elixir.Hexpm.Accounts.PasswordReset module, affecting versions before bb0e42091995945deef10556f58d046a52eb7884. This flaw allows for Account Takeover due to password reset tokens remaining valid indefinitely until used. With a CVSS score of 9.5 (CRITICAL), an attacker can exploit this by obtaining a previously leaked password reset email, even without current email access, to reset a victim's password. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2025-10-01, < 2026-03-05CPE matchmatch criteria | cpe:2.3:a:hex:hexpm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.