Ash Typescript
Ash-Project · 7 CVEs
CVE-2026-82731
LOW
Unescaped path parameters in AshTypescript generated TypeScript client allow request redirection
Sep 1, 2026
CVE-2026-74837
HIGH
Unbounded atom creation from client-supplied RPC field names in AshTypescript field formatter
Sep 1, 2026
CVE-2026-82733
MEDIUM
Route handler return value echoed into AshTypescript error response
Sep 1, 2026
CVE-2026-82732
MEDIUM
Declared argument constraints not enforced on AshTypescript typed controller routes
Sep 1, 2026
CVE-2026-82730
HIGH
Authorization-redacted field values disclosed through AshTypescript result normalization
Sep 1, 2026
CVE-2026-77950
MEDIUM
RPC error handler fails open in AshTypescript, disclosing unredacted errors
Sep 1, 2026
CVE-2026-77856
HIGH
Unbounded atom creation from typed struct field names in AshTypescript field selector
Sep 1, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-82731 | Unescaped path parameters in AshTypescript generated TypeScript client allow request redirection | LOW | 0.50% | Sep 1, 2026 |
| CVE-2026-74837 | Unbounded atom creation from client-supplied RPC field names in AshTypescript field formatter | HIGH | 0.55% | Sep 1, 2026 |
| CVE-2026-82733 | Route handler return value echoed into AshTypescript error response | MEDIUM | 0.55% | Sep 1, 2026 |
| CVE-2026-82732 | Declared argument constraints not enforced on AshTypescript typed controller routes | MEDIUM | 0.68% | Sep 1, 2026 |
| CVE-2026-82730 | Authorization-redacted field values disclosed through AshTypescript result normalization | HIGH | 0.50% | Sep 1, 2026 |
| CVE-2026-77950 | RPC error handler fails open in AshTypescript, disclosing unredacted errors | MEDIUM | 0.55% | Sep 1, 2026 |
| CVE-2026-77856 | Unbounded atom creation from typed struct field names in AshTypescript field selector | HIGH | 0.55% | Sep 1, 2026 |
Showing 1 to 7 of 7 CVEs