ash_typescript
Hex7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ash_typescriptpage 1 of 1
- CVE-2026-74837HIGHCVSS 8.7EG 8.7✓ Fixed in 0.18.02026-09-01
vulnerable: 0.1.0 ... 0.9.1 (51 versions)
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied RPC field names. AshTypescript.Field…
- CVE-2026-77856HIGHCVSS 8.2EG 8.2✓ Fixed in 0.18.02026-09-01
vulnerable: 0.11.0 ... 0.17.3 (26 versions)
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied typed struct field names. resolve_ty…
- CVE-2026-77950MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.18.02026-09-01
vulnerable: 0.10.0 ... 0.9.1 (36 versions)
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to receive unredacted internal error data by provoking an error shape the configured error handler …
- CVE-2026-82730HIGHCVSS 8.2EG 8.2✓ Fixed in 0.18.02026-09-01
vulnerable: 0.11.0 ... 0.17.3 (26 versions)
Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied. When a field policy denies an attribute, Ash substitutes %Ash.ForbiddenField{},…
- CVE-2026-82731LOWCVSS 2.3EG 2.3✓ Fixed in 0.18.02026-09-01
vulnerable: 0.15.0 ... 0.17.3 (9 versions)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who controls a path-parameter value to redirect a generated client's request, and the credentials attached to it, to an unin…
- CVE-2026-82732MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.18.02026-09-01
vulnerable: 0.15.0 ... 0.17.3 (9 versions)
Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argument values outside a declared allowlist or bound on typed-controller routes. AshTypescript.TypedController.RequestHandler in lib…
- CVE-2026-82733MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.18.02026-09-01
vulnerable: 0.15.0 ... 0.17.3 (9 versions)
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to read internal application data from an HTTP 500 response body. When a typed-controller route ha…
Check whether ash_typescript is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ash_typescript CVEs against the assets you own.
Start Free Scan →