decimal v3.0.0 enforces safer defaults. This is technically a breaking change, but for most use cases it should not require application changes. If needed, we recommend overriding the dependency explicitly:
MixAudit relies on the GitHub Advisory DB. It is unfortunately often a few days out of date. In this case as well.
We’re however working on integrating this directly as warnings in deps.get and hex.audit. (Currently only checks for retirement status; You can already see the vulnerabilities on hex.pm package pages).
The data there relies on OSV.dev and therefore directly contains EEF CNA, GHSA and other reporters, see OSV - Open Source Vulnerabilities
Thanks for the explanation, now I get the reason for this post I guess . I didn’t know it was absent from the GitHub Advisory DB, I assumed it was there already since it’s been assigned GHSA ID
Happy to know that you’re aware of it and there is work being done to improve the tools
Run mix hex.audit
Advisories:
Found packages with security advisories
decimal 3.1.1 - EEF-CVE-2026-32686 (MEDIUM)
aka: CVE-2026-32686, GHSA-rhv4-8758-jx7v
Unbounded exponent in decimal enables unauthenticated DoS
https://osv.dev/vulnerability/EEF-CVE-2026-32686
I am on 3.1.1 of decimal.
But is 3.1.1 really affected by this? If yes - then is there a version with mitigation in the works? I can skip the advisory, but I wonder what’s a proper way to handling it.
@gmile We had an error in the record. It has a defaultStatus of affected and declared more affected ranges.
Before a new release of our tooling yesterday, that error did not surface since defaultStatus was not supported. Now that it is, it correctly deduced that all versions are affected.
I have corrected it so that the defaultStatus is unaffected.