目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-81318— AshSql 不同租户数据泄露漏洞

一分钟漏洞结论

影响对象
ash-project ash_sql
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

ash-project 中的 ash_sql 存在一个不正确的授权漏洞:在基于模式(schema)的多租户应用程序中,调用者可能会接收到来自其他租户行的聚合值。 当对去重(distinct)查询进行聚合计算时, 仅依据 (仅包含 元组)重建外层查询,而没有携带 或 。在采用 多租户策略时,这些 prefix 字段中保存着租户的 schema 信息。因此,重建后的外层查询会读取仓库(repo)的默认 schema,而内部的相关子查询仍读取租户的 schema,两者仅通过主键进行连接。结果,聚合结果以及基于无 pref

CVSS 2.1 · Low
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-81318 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
来源: CVE Program / CVE List V5
Vulnerability Description
Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a distinct query, AshSql.AggregateQuery.add_single_aggs/5 rebuilds the outer query from query.from.source alone, which is only the {table, schema} tuple and does not carry query.prefix or query.from.prefix. For strategy(:context) multitenancy those hold the tenant schema, so the rebuilt outer query reads the repo's default schema while the inner correlated subquery still reads the tenant schema, and the two are joined only on primary key. The aggregate, and any relationship join added off the prefix-less binding, is then computed against the wrong tenant's rows. The neighbouring limit and exists branches instead wrap the query with subquery/1, which preserves the prefix. This issue affects ash_sql: from 0.1.0 before 0.7.1.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
ash-project ash_sql 0.1.0 ~ 0.7.1 cpe:2.3:a:ash-project:ash_sql:*:*:*:*:*:*:*:*
ash-project ash_sql dd092ed273dec7bd2194352f24a39229fc8ae68b ~ 3d95478cc9e1d5bfaf6144fe9b9793f29e5ab889 cpe:2.3:a:ash-project:ash_sql:*:*:*:*:*:*:*:*

二、漏洞 CVE-2026-81318 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-81318 的情报信息

登录查看更多情报信息。

CVE-2026-81318 补丁与修复 (1)

CVE-2026-81318 厂商安全公告 (2)

CVE-2026-81318 其他参考 (1)

同批安全公告 · ash-project · 2026-08-30 · 共 11 条

CVE-2026-75847 5.9 MEDIUM AshPaperTrail 敏感属性存储于公开变更映射
CVE-2026-77970 5.9 MEDIUM AshPaperTrail 嵌入式嵌套字段未脱敏漏洞
CVE-2026-78038 5.9 MEDIUM AshOban 参数注入覆盖主键与租户漏洞
CVE-2026-78228 5.9 MEDIUM Ash Oban 远程服务拒绝漏洞
CVE-2026-77454 5.9 MEDIUM AshSql 2.49 静默丢弃存在性过滤漏洞
CVE-2026-77831 2.1 LOW AshPaperTrail全量差异列表算法复杂度拒绝服务
CVE-2026-77846 2.1 LOW AshSqlite JSON路径注入漏洞
CVE-2026-78691 2.1 LOW AshSql 字符串搜索 LIKE 通配符注入漏洞
CVE-2026-80227 2.1 LOW Ash SQL 字符串修剪逻辑与内存处理不一致
CVE-2026-81316 2.1 LOW AshSql 同名聚合混淆漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-81318

暂无评论


发表评论