maennchen

maennchen

:warning: Security advisory: Decimal DoS vulnerability

A vulnerability has been published for decimal where very large exponents can cause excessive memory allocation and crash the BEAM VM.

Affected versions: decimal < 3.0.0
Fixed in: decimal 3.0.0
CVE: CVE-2026-32686
GHSA: GHSA-rhv4-8758-jx7v

We recommend updating immediately.

decimal v3.0.0 enforces safer defaults. This is technically a breaking change, but for most use cases it should not require application changes. If needed, we recommend overriding the dependency explicitly:

{:decimal, "~> 3.0", override: true}

Showing Posts 1 to 9

dimitarvp

dimitarvp

Just upgraded to 3.0.0 and ran a pretty slow financial test suite from scratch. No regressions! Great work, thank you.

Hermanverschooten

Hermanverschooten

Better upgrade to 3.1, 3.0 has a bug that causes an infinite loop.

It caused my tests to hang.

adamzapasnik

adamzapasnik

Thank you for reporting it.

Does anyone know/understand why mix deps.audit doesn’t report it?

maennchen

maennchen OP

MixAudit relies on the GitHub Advisory DB. It is unfortunately often a few days out of date. In this case as well.

We’re however working on integrating this directly as warnings in deps.get and hex.audit. (Currently only checks for retirement status; You can already see the vulnerabilities on hex.pm package pages).

The data there relies on OSV.dev and therefore directly contains EEF CNA, GHSA and other reporters, see OSV - Open Source Vulnerabilities

adamzapasnik

adamzapasnik

Thanks for the explanation, now I get the reason for this post I guess :stuck_out_tongue: . I didn’t know it was absent from the GitHub Advisory DB, I assumed it was there already since it’s been assigned GHSA ID :grimacing:

Happy to know that you’re aware of it and there is work being done to improve the tools :crossed_fingers:

dimitarvp

dimitarvp

Well I actually mistyped. I’m on 3.1.0 indeed.

gmile

gmile

If I run mix hex.audit today I get:

Run mix hex.audit
Advisories:
Found packages with security advisories
  decimal 3.1.1 - EEF-CVE-2026-32686 (MEDIUM)
    aka: CVE-2026-32686, GHSA-rhv4-8758-jx7v
    Unbounded exponent in decimal enables unauthenticated DoS
    https://osv.dev/vulnerability/EEF-CVE-2026-32686

I am on 3.1.1 of decimal.

But is 3.1.1 really affected by this? If yes - then is there a version with mitigation in the works? I can skip the advisory, but I wonder what’s a proper way to handling it.

maennchen

maennchen OP

@gmile We had an error in the record. It has a defaultStatus of affected and declared more affected ranges.

Before a new release of our tooling yesterday, that error did not surface since defaultStatus was not supported. Now that it is, it correctly deduced that all versions are affected.

I have corrected it so that the defaultStatus is unaffected.

gmile

gmile

Thank you for a quick fix, much appreciated!

— All posts loaded —

Where Next? Top

Trending in Discussions Top

AstonJ
As the title says, please share what you’ve been up to with Elixir. Whether that’s been learning it, looking into it, making stuff with i...
2977 94592 917
New
cblavier
Hey there, It’s been more than a year since we started using LiveView as our main UI library and building a whole library of UI componen...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
heathen
Quite interesting article Google brought me. Didn’t find any mentions about it here. What do you think in general? Would you use togethe...
New
mhanberg
Hi everyone! The first release candidate for the Expert language server project is now available! We’ve published a press release detai...
New
axelson
Hi there! :wave: @frigidcode and I (but mostly him) have been running an Elixir Book club, we’re almost done with Designing Elixir Syste...
New
budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
georgeguimaraes
Just published claude-code-elixir, a plugin marketplace for Claude Code with Elixir support. These are the plugins I’ve been using for my...
New
Dmk
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews