maennchen
Security advisory: Decimal DoS vulnerability
A vulnerability has been published for decimal where very large exponents can cause excessive memory allocation and crash the BEAM VM.
Affected versions: decimal < 3.0.0
Fixed in: decimal 3.0.0
CVE: CVE-2026-32686
GHSA: GHSA-rhv4-8758-jx7v
We recommend updating immediately.
decimal v3.0.0 enforces safer defaults. This is technically a breaking change, but for most use cases it should not require application changes. If needed, we recommend overriding the dependency explicitly:
{:decimal, "~> 3.0", override: true}
Trending in Discussions
A little off-topic, but I feel like people here have a good head on their shoulders.
I used to be quite good at making software. Was luc...
New
Hi there! :wave:
@frigidcode and I (but mostly him) have been running an Elixir Book club, we’re almost done with Designing Elixir Syste...
New
There has been a thread to discuss the Stack Overflow Developer Survey on this forum every year since 2018, so here’s yet another one for...
New
I’ve been using Emacs as my main code editor for more than a two years. It’s a custom build version although I’ve tried doom emacs and sp...
New
I love Elixir. It’s one of 2 programming languages I’ve ever fallen in love with.
But I don’t use it anymore.
Serverless was the promis...
New
Lately I’ve been thinking about how to organize components as a LiveView application grows. One of the pain points I’ve found (for myself...
New
What IDE or editor are you using for Elixir development?
Personally, I use Zed, and I really like it, but sometimes I wish there were a ...
New
Other Trending Topics
Edit: 2026 May 15 - This post is archived.
Mob is alive!!
Main docs: mob v0.7.11 — Documentation
A bit of explanation for the slightly c...
New
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
I fully migrated to my own harness from Anthropic/Gemini and I think it’s time to share it. Welcome DSH, the DeepSeek Harness, fully writ...
New
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
Emily is an Elixir library that runs Nx computations on Apple’s MLX. Install it as the default Nx backend and Nx, defn, Axon, Nx.Serving,...
New
(I just needed to vent somewhere and LinkedIn is full of hope, or hype, I’m not sure which exactly)
AI dream has many faces, but general...
New
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #ai
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #blog-post
- #elixirconf-us
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #elixirconf-eu
- #api
- #forms
- #security
- #metaprogramming










Showing Posts 1 to 9- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
dimitarvp
Just upgraded to 3.0.0 and ran a pretty slow financial test suite from scratch. No regressions! Great work, thank you.
Hermanverschooten
Better upgrade to 3.1, 3.0 has a bug that causes an infinite loop.
It caused my tests to hang.
adamzapasnik
Thank you for reporting it.
Does anyone know/understand why
mix deps.auditdoesn’t report it?maennchen
MixAudit relies on the GitHub Advisory DB. It is unfortunately often a few days out of date. In this case as well.
We’re however working on integrating this directly as warnings in
deps.getandhex.audit. (Currently only checks for retirement status; You can already see the vulnerabilities on hex.pm package pages).The data there relies on OSV.dev and therefore directly contains EEF CNA, GHSA and other reporters, see OSV - Open Source Vulnerabilities
adamzapasnik
Thanks for the explanation, now I get the reason for this post I guess
. I didn’t know it was absent from the GitHub Advisory DB, I assumed it was there already since it’s been assigned GHSA ID 
Happy to know that you’re aware of it and there is work being done to improve the tools
dimitarvp
Well I actually mistyped. I’m on 3.1.0 indeed.
gmile
If I run
mix hex.audittoday I get:I am on 3.1.1 of decimal.
But is 3.1.1 really affected by this? If yes - then is there a version with mitigation in the works? I can skip the advisory, but I wonder what’s a proper way to handling it.
maennchen
@gmile We had an error in the record. It has a
defaultStatusofaffectedand declared more affected ranges.Before a new release of our tooling yesterday, that error did not surface since
defaultStatuswas not supported. Now that it is, it correctly deduced that all versions are affected.I have corrected it so that the
defaultStatusisunaffected.gmile
Thank you for a quick fix, much appreciated!