CVE-2026-82743
- EPSS 0.13%
- Veröffentlicht 01.09.2026 03:37:24
- Zuletzt bearbeitet 01.09.2026 21:15:00
Uncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spin a scheduler thread at full CPU while the framework waits for it. Ash.Actions.Read.AsyncLimiter.await_at_least_one/1 (lib/ash/actions/read/async_lim...
CVE-2026-82742
- EPSS 0.13%
- Veröffentlicht 01.09.2026 03:35:18
- Zuletzt bearbeitet 01.09.2026 21:15:00
Uncontrolled Resource Consumption vulnerability in ash-project ash lets an attacker exhaust node memory by matching a filter that spans multiple to-many relationships in memory. Ash.Filter.Runtime matches a filter against an in-memory record by firs...
CVE-2026-82741
- EPSS 0.13%
- Veröffentlicht 01.09.2026 03:33:03
- Zuletzt bearbeitet 01.09.2026 21:15:00
Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the stored type tag of an Ash.Type.Union value that uses storage: :map_with_tag, bypassing that member's validation and any tag-based authorizati...
CVE-2026-82740
- EPSS 0.13%
- Veröffentlicht 01.09.2026 03:29:11
- Zuletzt bearbeitet 01.09.2026 21:15:00
Improper Input Validation vulnerability in ash-project ash fails to enforce the outer array constraints on a doubly-nested {:array, {:array, type}} attribute, letting invalid input pass validation. Ash.Type.apply_constraints/3 (lib/ash/type/type.ex)...
CVE-2026-82739
- EPSS 0.13%
- Veröffentlicht 01.09.2026 03:27:58
- Zuletzt bearbeitet 01.09.2026 21:15:00
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the stored value of a confirmed field to an actor who fails its confirmation check. Ash.Resource.Validation.Confirm's atomic implementation (atom...
CVE-2026-82738
- EPSS 0.14%
- Veröffentlicht 01.09.2026 03:26:23
- Zuletzt bearbeitet 01.09.2026 21:15:00
Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a record by storing a non-version-7 UUID in an Ash.Type.UUIDv7 attribute. Ash.Type.UUIDv7.cast_input/2 accepts any well-formed UUID string, i...
CVE-2026-82737
- EPSS 0.14%
- Veröffentlicht 01.09.2026 03:24:14
- Zuletzt bearbeitet 01.09.2026 21:15:00
Integer Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored vector and crash later reads of it by submitting a vector with more than 65,535 elements. Ash.Vector.new/1 (lib/ash/vector.ex) encodes a vector as <<di...
CVE-2026-82736
- EPSS 0.14%
- Veröffentlicht 01.09.2026 03:21:47
- Zuletzt bearbeitet 01.09.2026 21:15:00
Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-insensitive string value that violates its length or match constraints. Ash.Type.CiString.apply_constraints/2 (lib/ash/type/ci_stri...
CVE-2026-82735
- EPSS 0.14%
- Veröffentlicht 01.09.2026 03:19:36
- Zuletzt bearbeitet 01.09.2026 21:15:00
Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to force an expensive regular expression to run on input that a length constraint should have already rejected. Ash.Type.String.apply_constraints/2 (lib/ash/type/s...
CVE-2026-82734
- EPSS 0.13%
- Veröffentlicht 01.09.2026 03:17:15
- Zuletzt bearbeitet 01.09.2026 21:15:00
Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to submit a non-finite decimal value that bypasses numeric bounds constraints or fails later operations on the value. Ash.Type.Decimal cast input ...