Erlang/Elixir 生态下的 Ash Project 中 AshDoubleEntry 存在“替代编码处理不当”漏洞 漏洞描述: 中的 存在“替代编码处理不当”(Improper Handling of Alternate Encoding)漏洞,允许攻击者提交同一标识符的不同拼写形式,从而指向相同的数据记录。 技术细节: 将 128 位 ULID 表示为 26 个 Crockford Base-32 字符。但由于 ULID 的时间戳部分前 48 位仅使用 3 位信息,因此第一个字符在规范值范围内只能是 0
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash_double_entry | 0.1.0 ~ 1.0.19 |
cpe:2.3:a:ash-project:ash_double_entry:*:*:*:*:*:*:*:*
|
|
| ash-project | ash_double_entry | 1e5f7ce8ff25f519c904731a29eb1258324e561a ~ d3e688d300a581ae214b3ca7d95ef4de63fbb050 |
cpe:2.3:a:ash-project:ash_double_entry:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82753 | 8.2 HIGH | Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and c |
| CVE-2026-82586 | 8.2 HIGH | AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private at |
| CVE-2026-82755 | 6.3 MEDIUM | ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheab |
| CVE-2026-82758 | 6.3 MEDIUM | ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gat |
| CVE-2026-82754 | 6.3 MEDIUM | ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypas |
| CVE-2026-82757 | 6.3 MEDIUM | ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addre |
| CVE-2026-82756 | 6.3 MEDIUM | ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenti |
| CVE-2026-82584 | 2.3 LOW | Terminal escape sequence injection in the mix igniter.install confirmation prompt via pack |
No comments yet