Ash Project

Ash

28 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 01.09.2026 03:37:24
  • Zuletzt bearbeitet 01.09.2026 21:15:00

Uncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spin a scheduler thread at full CPU while the framework waits for it. Ash.Actions.Read.AsyncLimiter.await_at_least_one/1 (lib/ash/actions/read/async_lim...

  • EPSS 0.13%
  • Veröffentlicht 01.09.2026 03:35:18
  • Zuletzt bearbeitet 01.09.2026 21:15:00

Uncontrolled Resource Consumption vulnerability in ash-project ash lets an attacker exhaust node memory by matching a filter that spans multiple to-many relationships in memory. Ash.Filter.Runtime matches a filter against an in-memory record by firs...

  • EPSS 0.13%
  • Veröffentlicht 01.09.2026 03:33:03
  • Zuletzt bearbeitet 01.09.2026 21:15:00

Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the stored type tag of an Ash.Type.Union value that uses storage: :map_with_tag, bypassing that member's validation and any tag-based authorizati...

  • EPSS 0.13%
  • Veröffentlicht 01.09.2026 03:29:11
  • Zuletzt bearbeitet 01.09.2026 21:15:00

Improper Input Validation vulnerability in ash-project ash fails to enforce the outer array constraints on a doubly-nested {:array, {:array, type}} attribute, letting invalid input pass validation. Ash.Type.apply_constraints/3 (lib/ash/type/type.ex)...

  • EPSS 0.13%
  • Veröffentlicht 01.09.2026 03:27:58
  • Zuletzt bearbeitet 01.09.2026 21:15:00

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the stored value of a confirmed field to an actor who fails its confirmation check. Ash.Resource.Validation.Confirm's atomic implementation (atom...

  • EPSS 0.14%
  • Veröffentlicht 01.09.2026 03:26:23
  • Zuletzt bearbeitet 01.09.2026 21:15:00

Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a record by storing a non-version-7 UUID in an Ash.Type.UUIDv7 attribute. Ash.Type.UUIDv7.cast_input/2 accepts any well-formed UUID string, i...

  • EPSS 0.14%
  • Veröffentlicht 01.09.2026 03:24:14
  • Zuletzt bearbeitet 01.09.2026 21:15:00

Integer Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored vector and crash later reads of it by submitting a vector with more than 65,535 elements. Ash.Vector.new/1 (lib/ash/vector.ex) encodes a vector as <<di...

  • EPSS 0.14%
  • Veröffentlicht 01.09.2026 03:21:47
  • Zuletzt bearbeitet 01.09.2026 21:15:00

Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-insensitive string value that violates its length or match constraints. Ash.Type.CiString.apply_constraints/2 (lib/ash/type/ci_stri...

  • EPSS 0.14%
  • Veröffentlicht 01.09.2026 03:19:36
  • Zuletzt bearbeitet 01.09.2026 21:15:00

Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to force an expensive regular expression to run on input that a length constraint should have already rejected. Ash.Type.String.apply_constraints/2 (lib/ash/type/s...

  • EPSS 0.13%
  • Veröffentlicht 01.09.2026 03:17:15
  • Zuletzt bearbeitet 01.09.2026 21:15:00

Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to submit a non-finite decimal value that bypasses numeric bounds constraints or fails later operations on the value. Ash.Type.Decimal cast input ...