CVE-2026-67579
- EPSS 0.4%
- Veröffentlicht 12.08.2026 20:04:42
- Zuletzt bearbeitet 18.08.2026 14:53:39
Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injection or code execution depending on the data layer. ...
CVE-2026-69659
- EPSS 0.13%
- Veröffentlicht 09.08.2026 18:01:32
- Zuletzt bearbeitet 18.08.2026 15:38:34
Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:after] or page[...
CVE-2026-34593
- EPSS 0.42%
- Veröffentlicht 02.04.2026 17:42:26
- Zuletzt bearbeitet 24.07.2026 21:10:00
Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type.Module.cast_input/2 unconditionally creates a new Erlang atom via Module.concat([value]) for any user-supplied binary string that...