CVE-2026-59247: Gleam Insecure Unsigned Hex Metadatacve-2026-59247-gleam-insecure-unsigned-hex-metadata
Gleam extracted package `outer_checksum` or `requirements` directly from the unverified `hex::get_package_release` API response rather than the signed Hex registry metadata. An attacker capable of intercepting TLS traffic could forge the checksum, causing the application to verify and accept malicious package tarballs. Extract these security fields from the