ash_phoenix
Hex4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ash_phoenixpage 1 of 1
- CVE-2026-82724HIGHCVSS 7.6EG 7.6✓ Fixed in 2.3.252026-08-31
vulnerable: 2.1.26 ... 2.3.9 (27 versions)
Incorrect Authorization vulnerability in ash-project ash_phoenix invokes the SubdomainHook authorization callback with a nil tenant, so tenant-scoped access checks never see the tenant they are meant to enforce. AshPhoenix.LiveView.Subdom…
- CVE-2026-82725LOWCVSS 2.3EG 2.3✓ Fixed in 2.3.252026-08-31
vulnerable: 0.6.0-rc.1 ... 2.3.9 (131 versions)
Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_phoenix lets an attacker who controls filter form parameters filter across relationships the resource author marked non-public, turning the returned rows int…
- CVE-2026-82726MEDIUMCVSS 6.3EG 6.3✓ Fixed in 2.3.252026-08-31
vulnerable: 2.1.26 ... 2.3.9 (27 versions)
Permissive Regular Expression vulnerability in ash-project ash_phoenix lets a remote client select the tenant an Ash application uses, or degrade the request, by sending a crafted Host header. AshPhoenix.Helpers.get_subdomain/2 stripped t…
- CVE-2026-82727LOWCVSS 2.3EG 2.3✓ Fixed in 2.3.252026-08-31
vulnerable: 1.2.17 ... 2.3.9 (85 versions)
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_phoenix writes the entire raw submitted param map into an exception message, so secrets submitted alongside a union form field leak into logs, cr…
Check whether ash_phoenix is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ash_phoenix CVEs against the assets you own.
Start Free Scan →