Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81633— Unhandled KeyError in AshGraphql relay node resolution crashes queries via an unknown type segment

Quick assessment

Affected
ash-project ash_graphql
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ash_project 中 ash_graphql 存在输入验证不当漏洞,允许未经身份验证的客户端通过触发未处理的 KeyError 使 relay 节点(id: ...)查询崩溃。 AshGraphql.Graphql.Resolver 中的 resolve_node/2 使用 decode_relay_id/1 解码客户端提供的全局 ID。该函数仅对字符串进行 base64 解码并按“:”分割,但未验证类型段。解码出的类型直接传递给 Map.fetch!(type_to_domain_and_resource_

CVSS 6.9 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81633

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unhandled KeyError in AshGraphql relay node resolution crashes queries via an unknown type segment
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a relay node(id: ...) query with an unhandled KeyError. AshGraphql.Graphql.Resolver.resolve_node/2 decodes the client-supplied global ID with decode_relay_id/1, which only base64-decodes the string and splits it on : without validating the type segment. The decoded type is passed straight to Map.fetch!(type_to_domain_and_resource_map, type). Because fetch! raises on a missing key, a relay ID whose type segment is a valid atom that is not a relay-exposed type aborts the resolver before its resolve/2 clauses and their rescue handlers run, so the error never becomes a GraphQL error and may expose a stacktrace. Common resource names are easy to guess. The fix uses Map.fetch/2 and returns an Invalid node id error for unknown types. This issue affects ash_graphql: from 0.27.0 before 1.11.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ash-project ash_graphql 0.27.0 ~ 1.11.0 cpe:2.3:a:ash-project:ash_graphql:*:*:*:*:*:*:*:*
ash-project ash_graphql 365b3aedc6b36f020e6a2c7dce63fa569243bc4e ~ c8863ed8e5c21f1bfb6125f1d24e78443dfc6351 cpe:2.3:a:ash-project:ash_graphql:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-81633

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81633

登录查看更多情报信息。

Other References for CVE-2026-81633 (4)

Same Patch Batch · ash-project · 2026-08-30 · 20 CVEs total

CVE-2026-81636 8.7 HIGH Query-complexity limit bypass via first/last pagination arguments in AshGraphql enables de
CVE-2026-78699 7.2 HIGH rename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgres
CVE-2026-80223 7.1 HIGH Cross-tenant subscription disclosure in AshGraphql authorizes notifications in memory with
CVE-2026-78693 6.9 MEDIUM Incomplete redaction re-attaches the original error path in AshGraphql, leaking internal f
CVE-2026-77454 5.9 MEDIUM exists/2 predicate silently dropped on limited relationships with a parent() filter in Ash
CVE-2026-81319 5.9 MEDIUM Unsafe deserialization of decrypted terms enables node DoS in AshCloak
CVE-2026-75847 5.9 MEDIUM Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
CVE-2026-78228 5.9 MEDIUM Unbounded handle_error recursion enables denial of service in AshOban triggers
CVE-2026-78038 5.9 MEDIUM Job argument injection via :args overrides primary_key and tenant in AshOban
CVE-2026-77970 5.9 MEDIUM Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
CVE-2026-82367 2.3 LOW Re-entrant synchronous publish in AshGraphql subscription batcher delivers one subscriber'
CVE-2026-81643 2.3 LOW Broken access control in AshGraphql subscription batcher applies authorization suppression
CVE-2026-80227 2.1 LOW SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
CVE-2026-78691 2.1 LOW Unescaped backslash allows LIKE wildcard injection in AshSql string search
CVE-2026-81316 2.1 LOW Same-named aggregates with differing filters are conflated in AshSql
CVE-2026-81318 2.1 LOW Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
CVE-2026-81322 2.1 LOW Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
CVE-2026-77846 2.1 LOW JSON path injection via unescaped get_path segments in AshSqlite
CVE-2026-77831 2.1 LOW Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking

IV. Related Vulnerabilities

V. Comments for CVE-2026-81633

No comments yet


Leave a comment