CVE-2026-21622 - Password Reset Tokens Do Not Expire

CVE-2026-21622 - Password Reset Tokens Do Not Expire

CVE ID : CVE-2026-21622 Published : March 5, 2026, 9:18 p.m. | 25 minutes ago Description : Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows Account Takeover. Password reset tokens generated via the

CVE Details

Published
March 5, 2026