ash-project ash

19 known vulnerabilities in ash-project ash, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-93477 CVSS 5.9 medium Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the…
  • CVE-2026-86338 CVSS 6.0 medium Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see is referenced…
  • CVE-2026-82752 CVSS 5.9 medium Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size…
  • CVE-2026-82747 CVSS 5.9 medium Incorrect Authorization vulnerability in ash-project ash returns records that a runtime read policy denies to any actor. When a resource…
  • CVE-2026-82749 CVSS 5.9 medium Incorrect Authorization vulnerability in ash-project ash widens a relationship's parent(...) scoping filter to match unintended records…
  • CVE-2026-82748 CVSS 2.1 low Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while computing it under another…
  • CVE-2026-82746 CVSS 5.9 medium Missing Authorization vulnerability in ash-project ash allows an actor to update records forbidden by resource policies through the atomic…
  • CVE-2026-82745 CVSS 5.9 medium Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record when the ETS or Mnesia data…
  • CVE-2026-82744 CVSS 2.1 low Not Failing Securely (Failing Open) vulnerability in ash-project ash skips an Ash.Reactor change when the guard controlling it raises, so…
  • CVE-2026-82743 CVSS 2.1 low Uncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spin a scheduler thread at full CPU while…
  • CVE-2026-82742 CVSS 5.9 medium Uncontrolled Resource Consumption vulnerability in ash-project ash lets an attacker exhaust node memory by matching a filter that spans…
  • CVE-2026-82741 CVSS 2.1 low Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the stored type tag of an…
  • CVE-2026-82740 CVSS 2.1 low Improper Input Validation vulnerability in ash-project ash fails to enforce the outer array constraints on a doubly-nested {:array…
  • CVE-2026-82739 CVSS 2.1 low Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the stored value of a confirmed…
  • CVE-2026-82738 CVSS 5.9 medium Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a record by storing a…
  • CVE-2026-82737 CVSS 5.9 medium Integer Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored vector and crash later reads of it by…
  • CVE-2026-82736 CVSS 2.1 low Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-insensitive string…
  • CVE-2026-82735 CVSS 5.9 medium Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to force an expensive regular expression to run on…
  • CVE-2026-82734 CVSS 2.1 low Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to submit a non-finite decimal…