CVEs we hold for Ash-project
Records whose assigning authority named Ash-project as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-86338Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracleash-project ash
CVE-2026-82758ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client…ash-project ash_authentication_oauth2_server
CVE-2026-82757ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRFash-project ash_authentication_oauth2_server
CVE-2026-82756ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without…ash-project ash_authentication_oauth2_server
CVE-2026-82755ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling…ash-project ash_authentication_oauth2_server
CVE-2026-82754ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controlsash-project ash_authentication_oauth2_server
CVE-2026-82753Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in…ash-project ash_authentication_oauth2_server
CVE-2026-82752Ash string length constraints count graphemes, so a combining-mark string of any size passes max_lengthash-project ash
CVE-2026-82749Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped…ash-project ash
CVE-2026-82748Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under anotherash-project ash
CVE-2026-82747Ash.Policy.Authorizer returns records denied by a runtime read policy to any actorash-project ash
CVE-2026-82746Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden recordsash-project ash
CVE-2026-82745ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniquenessash-project ash
CVE-2026-82744Ash.Reactor change step fails open, skipping a change when its where guard raisesash-project ash
CVE-2026-82743Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async readsash-project ash
CVE-2026-82742Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memoryash-project ash
CVE-2026-82741Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusionash-project ash
CVE-2026-82740Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputsash-project ash
CVE-2026-82739Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch errorash-project ash
CVE-2026-82738Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of serviceash-project ash
CVE-2026-82737Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing readsash-project ash
CVE-2026-82736Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypassash-project ash
CVE-2026-82735Match regex runs on over-length input in Ash.Type.String, enabling regex denial of serviceash-project ash
CVE-2026-82734Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimalash-project ash
CVE-2026-82733Route handler return value echoed into AshTypescript error responseash-project ash_typescript
CVE-2026-82732Declared argument constraints not enforced on AshTypescript typed controller routesash-project ash_typescript
CVE-2026-82731Unescaped path parameters in AshTypescript generated TypeScript client allow request redirectionash-project ash_typescript
CVE-2026-82730Authorization-redacted field values disclosed through AshTypescript result normalizationash-project ash_typescript
CVE-2026-82727AshPhoenix Form.Auto leaks submitted params in an unknown _union_type error messageash-project ash_phoenix
CVE-2026-82726AshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary tenantash-project ash_phoenix
CVE-2026-82725AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related dataash-project ash_phoenix
CVE-2026-82724Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomainash-project ash_phoenix
CVE-2026-82722AshAdmin LiveView events intern atoms from client input, exhausting the atom table (node DoS)ash-project ash_admin
CVE-2026-82710Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadataash-project usage_rules
CVE-2026-82681Query-parameter injection in AshAdmin row-action links via unencoded string primary keysash-project ash_admin
CVE-2026-82673Path traversal in AshAdmin file uploads via unsanitized client filenameash-project ash_admin
CVE-2026-82586AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributesash-project ash_lua
CVE-2026-82584Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadataash-project igniter
CVE-2026-82580AshAi echoes raw tool exception messages into the conversation, disclosing internal detailsash-project ash_ai
CVE-2026-82579AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of serviceash-project ash_ai
CVE-2026-82564Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified recordsash-project ash_ai
CVE-2026-82367Re-entrant synchronous publish in AshGraphql subscription batcher delivers one subscriber's records to another's topicash-project ash_graphql
CVE-2026-81853AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracleash-project ash_admin
CVE-2026-81852AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypassash-project ash_admin
CVE-2026-81643Broken access control in AshGraphql subscription batcher applies authorization suppression to only the first…ash-project ash_graphql
CVE-2026-81638Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entryash-project ash_double_entry
CVE-2026-81636Query-complexity limit bypass via first/last pagination arguments in AshGraphql enables denial of serviceash-project ash_graphql
CVE-2026-81633Unhandled KeyError in AshGraphql relay node resolution crashes queries via an unknown type segmentash-project ash_graphql
CVE-2026-81322Cloaked plaintext leaks through a non-sensitive action argument in AshCloakash-project ash_cloak
CVE-2026-81319Unsafe deserialization of decrypted terms enables node DoS in AshCloakash-project ash_cloak
CVE-2026-81318Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSqlash-project ash_sql
CVE-2026-81316Same-named aggregates with differing filters are conflated in AshSqlash-project ash_sql
CVE-2026-81315MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto headerash-project ash_ai
CVE-2026-80227SQL string_trim removes only spaces, diverging from in-memory trimming in AshSqlash-project ash_sql
CVE-2026-80223Cross-tenant subscription disclosure in AshGraphql authorizes notifications in memory without a tenant-scoped readash-project ash_graphql
CVE-2026-78699rename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgresash-project ash_postgres
CVE-2026-78693Incomplete redaction re-attaches the original error path in AshGraphql, leaking internal field namesash-project ash_graphql
CVE-2026-78691Unescaped backslash allows LIKE wildcard injection in AshSql string searchash-project ash_sql
CVE-2026-78228Unbounded handle_error recursion enables denial of service in AshOban triggersash-project ash_oban
CVE-2026-78216AshLua eval read operations can read field-policy-protected fields via aggregatesash-project ash_lua
CVE-2026-78038Job argument injection via :args overrides primary_key and tenant in AshObanash-project ash_oban
CVE-2026-77970Sensitive fields nested in embedded values are not redacted in AshPaperTrail versionsash-project ash_paper_trail
CVE-2026-77956EEx template evaluation of prompt content in AshAi enables remote code executionash-project ash_ai
CVE-2026-77950RPC error handler fails open in AshTypescript, disclosing unredacted errorsash-project ash_typescript
CVE-2026-77856Unbounded atom creation from typed struct field names in AshTypescript field selectorash-project ash_typescript
CVE-2026-77850Stored XSS in AshAdmin relationship typeahead via unescaped label_field contentash-project ash_admin
CVE-2026-77846JSON path injection via unescaped get_path segments in AshSqliteash-project ash_sqlite
CVE-2026-77831Algorithmic-complexity denial of service in AshPaperTrail full-diff list trackingash-project ash_paper_trail
CVE-2026-77454exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSqlash-project ash_sql
CVE-2026-75847Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrailash-project ash_paper_trail
CVE-2026-75760AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing errorash-project ash_ai
CVE-2026-75757AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a sibling subdomainash-project ash_admin
CVE-2026-74837Unbounded atom creation from client-supplied RPC field names in AshTypescript field formatterash-project ash_typescript
CVE-2026-70395Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ashash-project ash
CVE-2026-69659Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keysetash-project ash
CVE-2026-34593Ash Framework: Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crashash-project ash
CVE-2025-48043Bypass and runtime policies that can never pass may be incorrectly applied in filter authorizationash-project ash
CVE-2025-48042Before action hooks may execute in certain scenarios despite a request being forbiddenash-project ash
CVE-2025-4754Missing Session Revocation on Logout in ash_authentication_phoenixash-project ash_authentication_phoenix
CVE-2024-49756AshPostgres empty, atomic, non-bulk actions, policy bypass for side-effects vulnerability.ash-project ash_postgres
84 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.