Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-69659— Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset

Quick assessment

Affected
ash-project ash
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Ash Framework是Ash Framework组织的一款基于Elixir的开发框架。 Ash Framework 1.17.0版本至3.31.1之前版本存在反序列化注入漏洞,该漏洞源于lib/ash/page/keyset.ex文件中的decode_values/2函数对客户端提供的page[:after]或page[:before]光标反序列化时未限制大小,且支持zlib压缩,导致内存消耗不受控制,攻击者可通过特制的keyset分页光标耗尽节点内存,造成拒绝服务。

CVSS 5.9 · Medium EPSS 0.36% · P28

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 2

VendorProduct Version RangeStatus
ash-project ash 1.17.0< 3.31.1 affected
f8fadc67e67c955bb68b3a8d642be13e2b7e8ca9< 1816b103af975221210478d61db20adcea700319 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-69659

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset
Source: CVE Program / CVE List V5
Vulnerability Description
Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:after] or page[:before] cursor in decode_values/2 in lib/ash/page/keyset.ex, which base64-decodes the value and passes it to :erlang.binary_to_term/2 without bounding its size. The Erlang external term format supports zlib-compressed payloads, which the decoder inflates transparently, so a cursor of a few kilobytes can allocate tens of megabytes of heap in a single call. Ash itself only ever encodes cursors uncompressed, so the decoder accepts a term shape its encoder never produces. Concurrent requests aggregate these allocations and can terminate the node. This issue affects ash: from 1.17.0 before 3.31.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5
Vulnerability Title
Ash Framework 反序列化漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Ash Framework是Ash Framework组织的一款基于Elixir的开发框架。 Ash Framework 1.17.0版本至3.31.1之前版本存在反序列化注入漏洞,该漏洞源于lib/ash/page/keyset.ex文件中的decode_values/2函数对客户端提供的page[:after]或page[:before]光标反序列化时未限制大小,且支持zlib压缩,导致内存消耗不受控制,攻击者可通过特制的keyset分页光标耗尽节点内存,造成拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
ash-project ash 1.17.0 ~ 3.31.1 cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
ash-project ash f8fadc67e67c955bb68b3a8d642be13e2b7e8ca9 ~ 1816b103af975221210478d61db20adcea700319 cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-69659

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-69659

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-69659 (1)

Vendor Advisories for CVE-2026-69659 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-69659

No comments yet


Leave a comment