缺陷描述:校验顺序错误——应在规范化之前进行校验 在 Ash 项目中, 允许攻击者存储一个大小写不敏感(case-insensitive)的字符串值,该值在规范化(即大小写折叠)后会违反其长度约束或匹配约束。 问题详情: (位于 )在接收到的原始值上校验 、 和 约束。然而,该类型在存储和比较时会按自身的大小写规则对字符串进行大小写折叠(case-folding)。由于校验在折叠之前执行,攻击者可以提交一个原始形式通过约束、但折叠后形式违反约束的值。 示例: 假设某个 约束要求大写字母,攻击者可以提交一个大写值。该
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash | 1.29.0-rc0 ~ 3.32.2 |
cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
|
|
| ash-project | ash | f6f5d194bfc7802bd32e48bf2eabd2d97a0109a4 ~ d8320b0127c8ef453679d70e5dd23a9506951d21 |
cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74837 | 8.7 HIGH | Unbounded atom creation from client-supplied RPC field names in AshTypescript field format |
| CVE-2026-77856 | 8.2 HIGH | Unbounded atom creation from typed struct field names in AshTypescript field selector |
| CVE-2026-82730 | 8.2 HIGH | Authorization-redacted field values disclosed through AshTypescript result normalization |
| CVE-2026-77950 | 6.3 MEDIUM | RPC error handler fails open in AshTypescript, disclosing unredacted errors |
| CVE-2026-82732 | 6.3 MEDIUM | Declared argument constraints not enforced on AshTypescript typed controller routes |
| CVE-2026-82733 | 6.3 MEDIUM | Route handler return value echoed into AshTypescript error response |
| CVE-2026-82738 | 5.9 MEDIUM | Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of |
| CVE-2026-82735 | 5.9 MEDIUM | Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service |
| CVE-2026-82737 | 5.9 MEDIUM | Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting |
| CVE-2026-82749 | 5.9 MEDIUM | Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is |
| CVE-2026-82742 | 5.9 MEDIUM | Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, |
| CVE-2026-82745 | 5.9 MEDIUM | ETS and Mnesia data layers overwrite an existing record on create instead of enforcing pri |
| CVE-2026-82746 | 5.9 MEDIUM | Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to for |
| CVE-2026-82731 | 2.3 LOW | Unescaped path parameters in AshTypescript generated TypeScript client allow request redir |
| CVE-2026-82739 | 2.1 LOW | Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic misma |
| CVE-2026-82740 | 2.1 LOW | Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs |
| CVE-2026-82741 | 2.1 LOW | Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion |
| CVE-2026-82734 | 2.1 LOW | Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal |
| CVE-2026-82743 | 2.1 LOW | Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads |
| CVE-2026-82744 | 2.1 LOW | Ash.Reactor change step fails open, skipping a change when its where guard raises |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet