Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82737— Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads

Quick assessment

Affected
ash-project ash
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 ash 项目的 库中存在一个整数溢出或回绕漏洞。攻击者可以通过提交一个包含超过 65,535 个元素的向量,破坏已存储的向量数据,导致后续对该向量的读取操作崩溃。 具体机制如下: (位于 )将向量编码为 ,后跟各元素浮点数。该实现将元素数量打包进一个 16 位字段,但未检查其取值范围。 当输入列表包含超过 65,535 个元素时,维度值会模 65,536 回绕,导致编码后的头部记录的维度与实际存储的浮点数数量不一致。 随后 根据回绕后的维度读取 个字节,因此每次读取被破坏的值时都会因解析错误而抛出异常,从而拒绝

CVSS 5.9 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82737

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads
Source: CVE Program / CVE List V5
Vulnerability Description
Integer Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored vector and crash later reads of it by submitting a vector with more than 65,535 elements. Ash.Vector.new/1 (lib/ash/vector.ex) encodes a vector as <<dim::unsigned-16, 0::unsigned-16>> followed by the element floats, packing the element count into a 16-bit field without checking its range. A list of more than 65,535 elements wraps the dimension modulo 65,536, so the encoded header records a dimension that disagrees with the number of stored floats. from_binary/1 later reads binary-size(dim)-unit(32) from the wrapped header, so every read of the corrupted value misparses and raises, denying access to the affected record. The fix rejects any vector whose dimension exceeds 65,535. This issue affects ash: from 2.14.13 before 3.32.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
整数溢出或超界折返
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ash-project ash 2.14.13 ~ 3.32.2 cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
ash-project ash e2855843ca4a9141dcd7f40f47227e13b43f0e00 ~ cef5eb7b0693f04d1699a36e02a4e09ce1e7bffe cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-82737

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82737

登录查看更多情报信息。

Other References for CVE-2026-82737 (4)

Same Patch Batch · ash-project · 2026-09-01 · 23 CVEs total

CVE-2026-74837 8.7 HIGH Unbounded atom creation from client-supplied RPC field names in AshTypescript field format
CVE-2026-77856 8.2 HIGH Unbounded atom creation from typed struct field names in AshTypescript field selector
CVE-2026-82730 8.2 HIGH Authorization-redacted field values disclosed through AshTypescript result normalization
CVE-2026-77950 6.3 MEDIUM RPC error handler fails open in AshTypescript, disclosing unredacted errors
CVE-2026-82732 6.3 MEDIUM Declared argument constraints not enforced on AshTypescript typed controller routes
CVE-2026-82733 6.3 MEDIUM Route handler return value echoed into AshTypescript error response
CVE-2026-82738 5.9 MEDIUM Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of
CVE-2026-82735 5.9 MEDIUM Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service
CVE-2026-82747 5.9 MEDIUM Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor
CVE-2026-82742 5.9 MEDIUM Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships,
CVE-2026-82745 5.9 MEDIUM ETS and Mnesia data layers overwrite an existing record on create instead of enforcing pri
CVE-2026-82746 5.9 MEDIUM Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to for
CVE-2026-82749 5.9 MEDIUM Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is
CVE-2026-82731 2.3 LOW Unescaped path parameters in AshTypescript generated TypeScript client allow request redir
CVE-2026-82740 2.1 LOW Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs
CVE-2026-82739 2.1 LOW Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic misma
CVE-2026-82741 2.1 LOW Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion
CVE-2026-82736 2.1 LOW Ash.Type.CiString validates length and match constraints before case folding, allowing con
CVE-2026-82734 2.1 LOW Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal
CVE-2026-82743 2.1 LOW Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads

Showing top 20 of 23 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-82737

No comments yet


Leave a comment