ash
Hex8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ashpage 1 of 1
- CVE-2025-48042HIGHCVSS 7.1EG 7.1✓ Fixed in 3.5.392025-09-07
vulnerable: 0.1.0 ... 3.5.9 (814 versions)
Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/b…
- CVE-2025-48043HIGHCVSS 8.6EG 8.6✓ Fixed in 3.6.22025-10-10
vulnerable: 0.1.0 ... 3.6.1 (821 versions)
Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/authorizer/authorizer.ex and program routines 'Elixir.Ash.Policy.Authorizer':strict_f…
- CVE-2025-48044HIGHCVSS 8.6EG 8.6✓ Fixed in 3.7.12025-10-17
vulnerable: 3.6.3, 3.7.0
Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue a…
- CVE-2026-34593HIGHCVSS 7.5EG 7.5✓ Fixed in 3.22.02026-04-02
vulnerable: 0.1.0 ... 3.9.0 (858 versions)
Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type.Module.cast_input/2 unconditionally creates a new Erlang atom via Module.concat([value]) for any user-supplied binary …
- CVE-2026-55736MEDIUMCVSS 5.9EG 5.9✓ Fixed in 3.29.32026-06-23
vulnerable: 3.0.0 ... 3.9.0 (225 versions)
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument that is intended to be controlled only by trusted server-side code.…
- CVE-2026-67579HIGHCVSS 7.4EG 7.4✓ Fixed in 3.31.32026-08-12
vulnerable: 1.17.0 ... 3.9.0 (829 versions)
Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injection or code execution depending on the da…
- CVE-2026-69659MEDIUMCVSS 5.5EG 5.5✓ Fixed in 3.31.12026-08-09
vulnerable: 1.17.0 ... 3.9.0 (827 versions)
Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:afte…
- CVE-2026-70395LOWCVSS 2.1EG 2.1✓ Fixed in 3.31.12026-08-09
vulnerable: 1.52.0-rc.11 ... 3.9.0 (571 versions)
Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to recover the secret value used to look it up. When manage_rela…
Check whether ash is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ash CVEs against the assets you own.
Start Free Scan →