Ash

Ash-Project · 27 CVEs

CVE-2026-93477
MEDIUM

Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash

Sep 25, 2026

CVE-2026-86338
MEDIUM

Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle

Sep 16, 2026

CVE-2026-82752
MEDIUM

Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length

Sep 5, 2026

CVE-2026-82747
MEDIUM

Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor

Sep 1, 2026

CVE-2026-82749
MEDIUM

Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped re…

Sep 1, 2026

CVE-2026-82748
LOW

Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another

Sep 1, 2026

CVE-2026-82746
MEDIUM

Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records

Sep 1, 2026

CVE-2026-82745
MEDIUM

ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness

Sep 1, 2026

CVE-2026-82744
LOW

Ash.Reactor change step fails open, skipping a change when its where guard raises

Sep 1, 2026

CVE-2026-82743
LOW

Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads

Sep 1, 2026

CVE-2026-82742
MEDIUM

Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory

Sep 1, 2026

CVE-2026-82741
LOW

Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion

Sep 1, 2026

CVE-2026-82740
LOW

Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs

Sep 1, 2026

CVE-2026-82739
LOW

Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error

Sep 1, 2026

CVE-2026-82738
MEDIUM

Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service

Sep 1, 2026

CVE-2026-82737
MEDIUM

Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads

Sep 1, 2026

CVE-2026-82736
LOW

Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypass

Sep 1, 2026

CVE-2026-82735
MEDIUM

Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service

Sep 1, 2026

CVE-2026-82734
LOW

Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal

Sep 1, 2026

CVE-2026-67579
HIGH

Filter expression injection via forged keyset pagination cursor in Ash

Aug 12, 2026

CVE-2026-70395
LOW

Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash

Aug 9, 2026

CVE-2026-69659
MEDIUM

Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset

Aug 9, 2026

CVE-2026-55736
MEDIUM

Private action arguments can be set by user input in Ash

Jun 23, 2026

CVE-2026-34593
HIGH

Ash Framework: Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash

Apr 2, 2026

CVE-2025-48044
HIGH

Authorization bypass when bypass policy condition evaluates to true

Oct 17, 2025

Showing 1 to 25 of 27 CVEs