目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-82367— AshGraphql 订阅分发器重入同步发布漏洞

一分钟漏洞结论

影响对象
ash-project ash_graphql
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

ash_graphql 中的“数据元素暴露给错误会话”漏洞,可能导致一个订阅(subscription)的已解析记录被错误地发送给另一个订阅者的主题。 具体机制如下: 通过 从进程字典中读取已解析的批次数据,随后无条件地删除该键值。这一做法仅在库自身拥有的任务(task)中是安全的。然而,在 和 回退模式下, 会在发布方进程的上下文中内联执行。如果外层 内部的解析器触发了另一个同步的 Ash 通知,则内层调用会在 键下找到外层运行遗留的值,并将其作为自己的结果发布到内层主题——而该主题对应的是另一个具有不同操作者(

CVSS 2.3 · Low
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-82367 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Re-entrant synchronous publish in AshGraphql subscription batcher delivers one subscriber's records to another's topic
来源: CVE Program / CVE List V5
Vulnerability Description
Exposure of Data Element to Wrong Session vulnerability in ash-project ash_graphql can deliver one subscription's resolved records to a different subscriber's topic. AshGraphql.Subscription.Batcher.do_send/5 reads the resolved batch from the process dictionary via Process.get(:batch_resolved) and then unconditionally deletes it. That is sound only inside a task the library owns. On the :backpressure_sync and :noproc fallbacks do_send/5 runs inline in the publishing caller's process, so if a resolver inside an outer do_send/5 triggers another synchronous Ash notification, the inner call finds the outer run's value still under :batch_resolved, adopts it as its own result, and publishes it to the inner topic, a different subscription document with a different actor and tenant. It then deletes the key, so the outer run publishes nothing. The key is not namespaced by run, so records cannot be told apart. The fix saves, clears, and restores :batch_resolved around each run. This issue affects ash_graphql: from 1.4.0 before 1.11.0.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
对错误会话暴露数据元素
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
ash-project ash_graphql 1.4.0 ~ 1.11.0 cpe:2.3:a:ash-project:ash_graphql:*:*:*:*:*:*:*:*
ash-project ash_graphql 3cb2c9870d050c7c4bba6c211aaed97d732f7e81 ~ b798ef5288664a0261990b19765558f168b718fb cpe:2.3:a:ash-project:ash_graphql:*:*:*:*:*:*:*:*

二、漏洞 CVE-2026-82367 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-82367 的情报信息

登录查看更多情报信息。

CVE-2026-82367 其他参考 (4)

同批安全公告 · ash-project · 2026-08-30 · 共 20 条

CVE-2026-81636 8.7 HIGH AshGraphql 分页参数复杂度过高导致拒绝服务漏洞
CVE-2026-78699 7.2 HIGH AshPostgres rename_tenant 租户访问漏洞
CVE-2026-80223 7.1 HIGH AshGraphql 跨租户订阅信息泄露漏洞
CVE-2026-78693 6.9 MEDIUM AshGraphql 敏感信息泄露漏洞
CVE-2026-81633 6.9 MEDIUM AshGraphql 未知类型段导致 KeyError
CVE-2026-77454 5.9 MEDIUM AshSql 2.49 静默丢弃存在性过滤漏洞
CVE-2026-81319 5.9 MEDIUM AshCloak 不安全反序列化导致节点拒绝服务漏洞
CVE-2026-75847 5.9 MEDIUM AshPaperTrail 敏感属性存储于公开变更映射
CVE-2026-78228 5.9 MEDIUM Ash Oban 远程服务拒绝漏洞
CVE-2026-78038 5.9 MEDIUM AshOban 参数注入覆盖主键与租户漏洞
CVE-2026-77970 5.9 MEDIUM AshPaperTrail 嵌入式嵌套字段未脱敏漏洞
CVE-2026-81643 2.3 LOW AshGraphql 批量订阅访问控制失效漏洞
CVE-2026-80227 2.1 LOW Ash SQL 字符串修剪逻辑与内存处理不一致
CVE-2026-81316 2.1 LOW AshSql 同名聚合混淆漏洞
CVE-2026-78691 2.1 LOW AshSql 字符串搜索 LIKE 通配符注入漏洞
CVE-2026-81322 2.1 LOW AshCloak 明文信息泄露漏洞
CVE-2026-81318 2.1 LOW AshSql 不同租户数据泄露漏洞
CVE-2026-77846 2.1 LOW AshSqlite JSON路径注入漏洞
CVE-2026-77831 2.1 LOW AshPaperTrail全量差异列表算法复杂度拒绝服务

IV. Related Vulnerabilities

V. Comments for CVE-2026-82367

暂无评论


发表评论