Ash
Ash-Project · 27 CVEs
Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash
Sep 25, 2026
Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle
Sep 16, 2026
Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length
Sep 5, 2026
Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor
Sep 1, 2026
Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped re…
Sep 1, 2026
Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another
Sep 1, 2026
Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records
Sep 1, 2026
ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness
Sep 1, 2026
Ash.Reactor change step fails open, skipping a change when its where guard raises
Sep 1, 2026
Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads
Sep 1, 2026
Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory
Sep 1, 2026
Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion
Sep 1, 2026
Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs
Sep 1, 2026
Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error
Sep 1, 2026
Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service
Sep 1, 2026
Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads
Sep 1, 2026
Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypass
Sep 1, 2026
Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service
Sep 1, 2026
Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal
Sep 1, 2026
Filter expression injection via forged keyset pagination cursor in Ash
Aug 12, 2026
Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash
Aug 9, 2026
Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset
Aug 9, 2026
Private action arguments can be set by user input in Ash
Jun 23, 2026
Ash Framework: Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash
Apr 2, 2026
Authorization bypass when bypass policy condition evaluates to true
Oct 17, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-93477 | Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash | MEDIUM | 0.20% | Sep 25, 2026 |
| CVE-2026-86338 | Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle | MEDIUM | 0.43% | Sep 16, 2026 |
| CVE-2026-82752 | Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length | MEDIUM | 0.18% | Sep 5, 2026 |
| CVE-2026-82747 | Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor | MEDIUM | 0.17% | Sep 1, 2026 |
| CVE-2026-82749 | Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records | MEDIUM | 0.17% | Sep 1, 2026 |
| CVE-2026-82748 | Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another | LOW | 0.17% | Sep 1, 2026 |
| CVE-2026-82746 | Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records | MEDIUM | 0.17% | Sep 1, 2026 |
| CVE-2026-82745 | ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness | MEDIUM | 0.17% | Sep 1, 2026 |
| CVE-2026-82744 | Ash.Reactor change step fails open, skipping a change when its where guard raises | LOW | 0.19% | Sep 1, 2026 |
| CVE-2026-82743 | Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads | LOW | 0.18% | Sep 1, 2026 |
| CVE-2026-82742 | Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory | MEDIUM | 0.18% | Sep 1, 2026 |
| CVE-2026-82741 | Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion | LOW | 0.19% | Sep 1, 2026 |
| CVE-2026-82740 | Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs | LOW | 0.18% | Sep 1, 2026 |
| CVE-2026-82739 | Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error | LOW | 0.18% | Sep 1, 2026 |
| CVE-2026-82738 | Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service | MEDIUM | 0.18% | Sep 1, 2026 |
| CVE-2026-82737 | Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads | MEDIUM | 0.18% | Sep 1, 2026 |
| CVE-2026-82736 | Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypass | LOW | 0.18% | Sep 1, 2026 |
| CVE-2026-82735 | Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service | MEDIUM | 0.18% | Sep 1, 2026 |
| CVE-2026-82734 | Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal | LOW | 0.19% | Sep 1, 2026 |
| CVE-2026-67579 | Filter expression injection via forged keyset pagination cursor in Ash | HIGH | 0.61% | Aug 12, 2026 |
| CVE-2026-70395 | Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash | LOW | 0.20% | Aug 9, 2026 |
| CVE-2026-69659 | Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset | MEDIUM | 0.36% | Aug 9, 2026 |
| CVE-2026-55736 | Private action arguments can be set by user input in Ash | MEDIUM | 0.37% | Jun 23, 2026 |
| CVE-2026-34593 | Ash Framework: Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash | HIGH | 0.52% | Apr 2, 2026 |
| CVE-2025-48044 | Authorization bypass when bypass policy condition evaluates to true | HIGH | 0.66% | Oct 17, 2025 |
Showing 1 to 25 of 27 CVEs