ash
Hex28 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ashpage 1 of 1
- CVE-2025-48042HIGHCVSS 7.1EG 7.1fixed in 3.5.392025-09-07
vulnerable: 0.1.0 ... 3.5.9 (814 versions)
Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ash: from 0.1.1 before 3.5.39.
- CVE-2025-48043HIGHCVSS 8.6EG 8.6fixed in 3.6.22025-10-10
vulnerable: 0.1.0 ... 3.6.1 (821 versions)
Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 0.1.1 before 3.6.2.
- CVE-2025-48044HIGHCVSS 8.6EG 8.6fixed in 3.7.12025-10-17
vulnerable: 3.6.3, 3.7.0
Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 3.6.3 before 3.7.1.
- CVE-2026-101028MEDIUMCVSS 6.0EG 6.03.34.6 (the fix for one version range)2026-10-09
vulnerable: 2.10.0 ... 3.9.0 (497 versions)
Incorrect Authorization vulnerability in ash-project ash allows an actor to infer data in related records they cannot read via Ash.count/2, Ash.exists/2 and Ash.aggregate/3. Ash.Actions.Aggregate.run/4 (lib/ash/actions/aggregate.ex) appli…
- CVE-2026-34593HIGHCVSS 7.5EG 7.5fixed in 3.22.02026-04-02
vulnerable: 0.1.0 ... 3.9.0 (858 versions)
Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type.Module.cast_input/2 unconditionally creates a new Erlang atom via Module.concat([value]) for any user-supplied binary …
- CVE-2026-55736MEDIUMCVSS 5.9EG 5.9fixed in 3.29.32026-06-23
vulnerable: 3.0.0 ... 3.9.0 (225 versions)
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument that is intended to be controlled only by trusted server-side code.…
- CVE-2026-67579HIGHCVSS 7.4EG 7.4fixed in 3.31.32026-08-12
vulnerable: 1.17.0 ... 3.9.0 (829 versions)
Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injection or code execution depending on the da…
- CVE-2026-69659MEDIUMCVSS 5.5EG 5.5fixed in 3.31.12026-08-09
vulnerable: 1.17.0 ... 3.9.0 (827 versions)
Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:afte…
- CVE-2026-70395LOWCVSS 2.1EG 2.1fixed in 3.31.12026-08-09
vulnerable: 1.52.0-rc.11 ... 3.9.0 (571 versions)
Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to recover the secret value used to look it up. When manage_rela…
- CVE-2026-82734LOWCVSS 2.1EG 2.1fixed in 3.32.22026-09-01
vulnerable: 1.28.0 ... 3.9.0 (791 versions)
Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to submit a non-finite decimal value that bypasses numeric bounds constraints or fails later operations on the value. Ash.Type.Decimal …
- CVE-2026-82735MEDIUMCVSS 5.9EG 5.9fixed in 3.32.22026-09-01
vulnerable: 0.10.0 ... 3.9.0 (876 versions)
Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to force an expensive regular expression to run on input that a length constraint should have already rejected. Ash.Type.String.apply_constraints/2 (lib…
- CVE-2026-82736LOWCVSS 2.1EG 2.1fixed in 3.32.22026-09-01
vulnerable: 1.29.0-rc0 ... 3.9.0 (789 versions)
Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-insensitive string value that violates its length or match constraints. Ash.Type.CiString.apply_constraints/2 (lib/ash/t…
- CVE-2026-82737MEDIUMCVSS 5.9EG 5.9fixed in 3.32.22026-09-01
vulnerable: 2.14.13 ... 3.9.0 (373 versions)
Integer Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored vector and crash later reads of it by submitting a vector with more than 65,535 elements. Ash.Vector.new/1 (lib/ash/vector.ex) encodes a vec…
- CVE-2026-82738MEDIUMCVSS 5.9EG 5.9fixed in 3.32.22026-09-01
vulnerable: 3.10.0 ... 3.9.0 (75 versions)
Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a record by storing a non-version-7 UUID in an Ash.Type.UUIDv7 attribute. Ash.Type.UUIDv7.cast_input/2 accepts any well-formed UUI…
- CVE-2026-82739LOWCVSS 2.1EG 2.1fixed in 3.32.22026-09-01
vulnerable: 2.17.20 ... 3.9.0 (322 versions)
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the stored value of a confirmed field to an actor who fails its confirmation check. Ash.Resource.Validation.Confirm's atomic implement…
- CVE-2026-82740LOWCVSS 2.1EG 2.1fixed in 3.32.22026-09-01
vulnerable: 2.16.1 ... 3.9.0 (343 versions)
Improper Input Validation vulnerability in ash-project ash fails to enforce the outer array constraints on a doubly-nested {:array, {:array, type}} attribute, letting invalid input pass validation. Ash.Type.apply_constraints/3 (lib/ash/ty…
- CVE-2026-82741LOWCVSS 2.1EG 2.1fixed in 3.32.22026-09-01
vulnerable: 2.14.18 ... 3.9.0 (368 versions)
Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the stored type tag of an Ash.Type.Union value that uses storage: :map_with_tag, bypassing that member's validation and any tag-based …
- CVE-2026-82742MEDIUMCVSS 5.9EG 5.9fixed in 3.32.22026-09-01
vulnerable: 1.29.0-rc0 ... 3.9.0 (789 versions)
Uncontrolled Resource Consumption vulnerability in ash-project ash lets an attacker exhaust node memory by matching a filter that spans multiple to-many relationships in memory. Ash.Filter.Runtime matches a filter against an in-memory rec…
- CVE-2026-82743LOWCVSS 2.1EG 2.1fixed in 3.32.22026-09-01
vulnerable: 2.19.0 ... 3.9.0 (314 versions)
Uncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spin a scheduler thread at full CPU while the framework waits for it. Ash.Actions.Read.AsyncLimiter.await_at_least_one/1 (lib/ash/actions/rea…
- CVE-2026-82744LOWCVSS 2.1EG 2.1fixed in 3.32.22026-09-01
vulnerable: 3.0.0 ... 3.9.0 (263 versions)
Not Failing Securely (Failing Open) vulnerability in ash-project ash skips an Ash.Reactor change when the guard controlling it raises, so a change meant to run does not. An Ash.Reactor change step can be gated by where validations that de…
- CVE-2026-82745MEDIUMCVSS 5.9EG 5.9fixed in 3.32.22026-09-01
vulnerable: 0.10.0 ... 3.9.0 (890 versions)
Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record when the ETS or Mnesia data layer is used, because neither enforced primary-key uniqueness on insert. Unlike a SQL data layer, whos…
- CVE-2026-82746MEDIUMCVSS 5.9EG 5.9fixed in 3.32.22026-09-01
vulnerable: 3.29.0 ... 3.32.1 (12 versions)
Missing Authorization vulnerability in ash-project ash allows an actor to update records forbidden by resource policies through the atomic path of Ash.update_many/4. Ash.update_many/4 runs as a single atomic statement (a data-layer update…
- CVE-2026-82747MEDIUMCVSS 5.9EG 5.9fixed in 3.32.22026-09-01
vulnerable: 3.10.0 ... 3.9.0 (153 versions)
Incorrect Authorization vulnerability in ash-project ash returns records that a runtime read policy denies to any actor. When a resource has an access_type :runtime read policy (a check evaluated per record rather than compiled to a filte…
- CVE-2026-82748LOWCVSS 2.1EG 2.1fixed in 3.32.22026-09-01
vulnerable: 3.10.0 ... 3.9.0 (109 versions)
Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while computing it under another, so an aggregate can run with policies that do not match the action it was authorized against. Ash.Act…
- CVE-2026-82749MEDIUMCVSS 5.9EG 5.9fixed in 3.32.22026-09-01
vulnerable: 3.13.2 ... 3.32.1 (56 versions)
Incorrect Authorization vulnerability in ash-project ash widens a relationship's parent(...) scoping filter to match unintended records when the referenced parent field cannot be resolved. Loading a relationship whose filter references pa…
- CVE-2026-82752MEDIUMCVSS 5.9EG 5.9fixed in 3.33.02026-09-05
vulnerable: 0.10.0 ... 3.9.0 (878 versions)
Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in an attribute whose length constraint should bound it. Ash measures string length with Elixir's St…
- CVE-2026-86338MEDIUMCVSS 6.0EG 6.0fixed in 3.33.42026-09-16
vulnerable: 2.11.0 ... 3.9.0 (415 versions)
Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see is referenced in a filter, it is replaced with an expression that evaluates to nil, so a filter cannot be used as …
- CVE-2026-93477MEDIUMCVSS 5.9EG 5.9fixed in 3.33.112026-09-25
vulnerable: 2.17.15 ... 3.9.0 (340 versions)
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the bulk destroy and bulk update paths. Action arguments declar…
Check whether ash is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ash CVEs against the assets you own.
Book a Demo →