CVE-2026-67579
- EPSS 0.4%
- Veröffentlicht 12.08.2026 20:04:42
- Zuletzt bearbeitet 18.08.2026 14:53:39
Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injection or code execution depending on the data layer. ...
CVE-2026-70395
- EPSS 0.14%
- Veröffentlicht 09.08.2026 18:17:07
- Zuletzt bearbeitet 12.08.2026 20:52:13
Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to recover the secret value used to look it up. When manage_relationship is...
CVE-2026-69659
- EPSS 0.13%
- Veröffentlicht 09.08.2026 18:01:32
- Zuletzt bearbeitet 18.08.2026 15:38:34
Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:after] or page[...
CVE-2026-55736
- EPSS 0.15%
- Veröffentlicht 23.06.2026 18:21:13
- Zuletzt bearbeitet 09.07.2026 16:16:45
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument that is intended to be controlled only by trusted server-side code. Action ar...
CVE-2026-34593
- EPSS 0.42%
- Veröffentlicht 02.04.2026 17:42:26
- Zuletzt bearbeitet 24.07.2026 21:10:00
Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type.Module.cast_input/2 unconditionally creates a new Erlang atom via Module.concat([value]) for any user-supplied binary string that...
CVE-2025-48044
- EPSS 0.81%
- Veröffentlicht 17.10.2025 13:52:53
- Zuletzt bearbeitet 24.07.2026 15:17:07
Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash:...
CVE-2025-48043
- EPSS 0.46%
- Veröffentlicht 10.10.2025 15:57:29
- Zuletzt bearbeitet 24.07.2026 15:17:07
Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/authorizer/authorizer.ex and program routines 'Elixir.Ash.Policy.Authorizer':strict_filters/2. ...
CVE-2025-48042
- EPSS 0.31%
- Veröffentlicht 07.09.2025 16:01:01
- Zuletzt bearbeitet 24.07.2026 15:17:06
Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, lib...