目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-77950— AshTypescript RPC 错误处理程序未脱敏错误

一分钟漏洞结论

影响对象
ash-project ash_typescript
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

漏洞描述翻译: ash-project 的 ash_typescript 中存在“生成包含敏感信息的错误消息”漏洞,使得未认证的攻击者能够通过触发一种已配置的错误处理器未能匹配的错误形态,从而接收到未经脱敏的内部错误数据。 在 中的 是应用端在错误到达客户端前进行脱敏或抑制错误的唯一钩子,返回 会完全丢弃该错误。其 子句仅记录一条警告日志,然后返回原始的错误映射(即处理器执行前的错误)。由于错误处理器通常被编写为针对预期错误形态的模式匹配函数,当遇到未匹配的错误形态时,会抛出 ,从而将原始的错误对象(包括 中携带的

CVSS 6.3 · Medium
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-77950 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
RPC error handler fails open in AshTypescript, disclosing unredacted errors
来源: CVE Program / CVE List V5
Vulnerability Description
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to receive unredacted internal error data by provoking an error shape the configured error handler does not match. apply_error_handler/3 in lib/ash_typescript/rpc/errors.ex is the only hook an application has for redacting or suppressing errors before they reach the client, with a nil return dropping the error entirely. Its rescue clause logs a warning and then returns the original, pre-handler error map. Error handlers are conventionally written as pattern-matching functions over expected error shapes, so an unmatched shape raises FunctionClauseError and the raw transformed error, including any secrets carried in vars, is emitted instead. An intent to suppress an error becomes an intent to publish it. The rescue catches exceptions only, so a handler that throws or exits still propagates. This issue affects ash_typescript: from 0.8.0 before 0.18.0.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
通过错误消息导致的信息暴露
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
ash-project ash_typescript 0.8.0 ~ 0.18.0 cpe:2.3:a:ash-project:ash_typescript:*:*:*:*:*:*:*:*
ash-project ash_typescript cb01cc8749e5a2a17fb45aedbe75df30a9f1126e ~ 59d8e985a98cf2e01794dbe5b919b897a95311f4 cpe:2.3:a:ash-project:ash_typescript:*:*:*:*:*:*:*:*

二、漏洞 CVE-2026-77950 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-77950 的情报信息

登录查看更多情报信息。

CVE-2026-77950 补丁与修复 (1)

CVE-2026-77950 厂商安全公告 (1)

CVE-2026-77950 其他参考 (2)

同批安全公告 · ash-project · 2026-09-01 · 共 20 条

CVE-2026-74837 8.7 HIGH AshTypescript RPC 字段创建无限原子漏洞
CVE-2026-77856 8.2 HIGH AshTypescript 无界原子创建漏洞
CVE-2026-82730 8.2 HIGH Ash Typescript 授权字段通过结果规范化泄露漏洞
CVE-2026-82732 6.3 MEDIUM Ash TypeScript 控制器路由参数约束未强制
CVE-2026-82733 6.3 MEDIUM AshTypescript 路由处理程序 返回值错误回显
CVE-2026-82737 5.9 MEDIUM Ash.Vector 向量头部处理缺陷
CVE-2026-82735 5.9 MEDIUM Ash.Type.String 正则输入过长拒绝服务漏洞
CVE-2026-82746 5.9 MEDIUM Ash ORM update_many 原子操作资源策略授权绕过漏洞
CVE-2026-82738 5.9 MEDIUM Ash.Type.UUIDv7 拒绝服务漏洞
CVE-2026-82742 5.9 MEDIUM Ash.Filter.Runtime 内存耗尽漏洞
CVE-2026-82745 5.9 MEDIUM ETS/Mnesia 数据层主键非唯一性缺陷
CVE-2026-82731 2.3 LOW AshTypescript 客户端请求重定向漏洞
CVE-2026-82739 2.1 LOW Ash.Resource.Validation.Confirm 字段值泄露漏洞
CVE-2026-82736 2.1 LOW Ash Type CiString 字符串约束绕过漏洞
CVE-2026-82740 2.1 LOW Ash.Type 嵌套数组输入约束失效漏洞
CVE-2026-82734 2.1 LOW Ash 框架 Ash.Type.Decimal 无限值绕过边界约束漏洞
CVE-2026-82741 2.1 LOW Ash.Type.Union 序列化标签混淆漏洞
CVE-2026-82743 2.1 LOW Ash.Actions.Read.AsyncLimiter 调度器忙等漏洞
CVE-2026-82744 2.1 LOW Ash.Reactor 守卫异常时跳过变更失败

IV. Related Vulnerabilities

V. Comments for CVE-2026-77950

暂无评论


发表评论