CVE-2026-94201
- EPSS 0.3%
- Veröffentlicht 05.10.2026 19:19:51
- Zuletzt bearbeitet 06.10.2026 15:03:59
Ash stores :atom-typed attributes as strings and compares them as strings. When such an attribute is referenced in a filter, the comparison value is coerced through Ash.Type.Atom. Because the type defined no coerce/2 callback, coercion fell back to t...
CVE-2026-93477
- EPSS 0.2%
- Veröffentlicht 25.09.2026 07:08:55
- Zuletzt bearbeitet 25.09.2026 14:17:23
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the bulk destroy and bulk update paths. Action arguments declared with pub...
- EPSS 0.32%
- Veröffentlicht 16.09.2026 08:28:44
- Zuletzt bearbeitet 16.09.2026 20:38:33
Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see is referenced in a filter, it is replaced with an expression that evaluates to nil, so a filter cannot be used as a yes/no or...
CVE-2026-82752
- EPSS 0.13%
- Veröffentlicht 05.09.2026 17:16:16
- Zuletzt bearbeitet 08.09.2026 19:20:01
Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in an attribute whose length constraint should bound it. Ash measures string length with Elixir's String.length...
CVE-2026-82747
- EPSS 0.12%
- Veröffentlicht 01.09.2026 04:14:57
- Zuletzt bearbeitet 01.09.2026 21:15:00
Incorrect Authorization vulnerability in ash-project ash returns records that a runtime read policy denies to any actor. When a resource has an access_type :runtime read policy (a check evaluated per record rather than compiled to a filter), Ash.Pol...
CVE-2026-82749
- EPSS 0.12%
- Veröffentlicht 01.09.2026 03:54:12
- Zuletzt bearbeitet 01.09.2026 21:15:00
Incorrect Authorization vulnerability in ash-project ash widens a relationship's parent(...) scoping filter to match unintended records when the referenced parent field cannot be resolved. Loading a relationship whose filter references parent(...) r...
CVE-2026-82748
- EPSS 0.12%
- Veröffentlicht 01.09.2026 03:52:01
- Zuletzt bearbeitet 01.09.2026 21:15:00
Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while computing it under another, so an aggregate can run with policies that do not match the action it was authorized against. Ash.Actions.Aggreg...
CVE-2026-82746
- EPSS 0.12%
- Veröffentlicht 01.09.2026 03:47:14
- Zuletzt bearbeitet 01.09.2026 21:15:00
Missing Authorization vulnerability in ash-project ash allows an actor to update records forbidden by resource policies through the atomic path of Ash.update_many/4. Ash.update_many/4 runs as a single atomic statement (a data-layer update_many, for ...
CVE-2026-82745
- EPSS 0.12%
- Veröffentlicht 01.09.2026 03:42:28
- Zuletzt bearbeitet 01.09.2026 21:15:00
Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record when the ETS or Mnesia data layer is used, because neither enforced primary-key uniqueness on insert. Unlike a SQL data layer, whose unique pr...
CVE-2026-82744
- EPSS 0.13%
- Veröffentlicht 01.09.2026 03:39:42
- Zuletzt bearbeitet 01.09.2026 21:15:00
Not Failing Securely (Failing Open) vulnerability in ash-project ash skips an Ash.Reactor change when the guard controlling it raises, so a change meant to run does not. An Ash.Reactor change step can be gated by where validations that decide whethe...