以下是该漏洞描述的中文翻译: ash-project 中 ash_sql 存在一个不正确的比较(Incorrect Comparison)漏洞。攻击者可以通过在字符串字段中填充制表符(tab)、换行符(newline)、回车符(carriage return)或换页符(form feed)字符,从而绕过数据库中经过修剪的“唯一性”或“相等性”检查,而这些输入在内存中的相同表达式中可能会失败(或者情况相反)。 编译为基于 Elixir 字符串构建的 模式,其中 是单个空格(码点 32)的转义字符,而不是正则表达式中的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash_sql | 0.1.0 ~ 0.7.1 |
cpe:2.3:a:ash-project:ash_sql:*:*:*:*:*:*:*:*
|
|
| ash-project | ash_sql | dd092ed273dec7bd2194352f24a39229fc8ae68b ~ 1b11b5d8bc5321e2e6acac21594ef08f61986117 |
cpe:2.3:a:ash-project:ash_sql:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75847 | 5.9 MEDIUM | Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail |
| CVE-2026-77970 | 5.9 MEDIUM | Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions |
| CVE-2026-78038 | 5.9 MEDIUM | Job argument injection via :args overrides primary_key and tenant in AshOban |
| CVE-2026-78228 | 5.9 MEDIUM | Unbounded handle_error recursion enables denial of service in AshOban triggers |
| CVE-2026-77454 | 5.9 MEDIUM | exists/2 predicate silently dropped on limited relationships with a parent() filter in Ash |
| CVE-2026-77831 | 2.1 LOW | Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking |
| CVE-2026-77846 | 2.1 LOW | JSON path injection via unescaped get_path segments in AshSqlite |
| CVE-2026-81318 | 2.1 LOW | Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql |
| CVE-2026-78691 | 2.1 LOW | Unescaped backslash allows LIKE wildcard injection in AshSql string search |
| CVE-2026-81316 | 2.1 LOW | Same-named aggregates with differing filters are conflated in AshSql |
No comments yet