ash 项目(ash-project/ash)中存在“包含敏感信息的错误消息生成”漏洞,导致在确认检查失败时,会将已存储的字段值暴露给未能通过确认的访问者。 具体来说, 的原子化实现(位于 中的 )在构造“不匹配”错误时,将其中的 字段设置为待确认的字段值。当访问者仅提交了确认参数而未提供该字段本身的值时,通过 解析,该 会解析为该字段当前数据库中存储的值。因此,不匹配错误消息中会回显该存储值。 对于保护敏感属性(如密码、令牌、个人信息等)的确认校验,攻击者(访问者)可以故意提交一个错误的确认值,从而从返回的错误消
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash | 2.17.20 ~ 3.32.2 |
cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
|
|
| ash-project | ash | fadecf3ee95640bd3bc7298df4799e0375537fd2 ~ 7dfe5f0b1ba4267580ded947dc861351d4dc8e2b |
cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74837 | 8.7 HIGH | Unbounded atom creation from client-supplied RPC field names in AshTypescript field format |
| CVE-2026-77856 | 8.2 HIGH | Unbounded atom creation from typed struct field names in AshTypescript field selector |
| CVE-2026-82730 | 8.2 HIGH | Authorization-redacted field values disclosed through AshTypescript result normalization |
| CVE-2026-77950 | 6.3 MEDIUM | RPC error handler fails open in AshTypescript, disclosing unredacted errors |
| CVE-2026-82732 | 6.3 MEDIUM | Declared argument constraints not enforced on AshTypescript typed controller routes |
| CVE-2026-82733 | 6.3 MEDIUM | Route handler return value echoed into AshTypescript error response |
| CVE-2026-82737 | 5.9 MEDIUM | Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting |
| CVE-2026-82735 | 5.9 MEDIUM | Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service |
| CVE-2026-82747 | 5.9 MEDIUM | Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor |
| CVE-2026-82738 | 5.9 MEDIUM | Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of |
| CVE-2026-82742 | 5.9 MEDIUM | Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, |
| CVE-2026-82745 | 5.9 MEDIUM | ETS and Mnesia data layers overwrite an existing record on create instead of enforcing pri |
| CVE-2026-82746 | 5.9 MEDIUM | Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to for |
| CVE-2026-82749 | 5.9 MEDIUM | Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is |
| CVE-2026-82731 | 2.3 LOW | Unescaped path parameters in AshTypescript generated TypeScript client allow request redir |
| CVE-2026-82740 | 2.1 LOW | Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs |
| CVE-2026-82741 | 2.1 LOW | Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion |
| CVE-2026-82736 | 2.1 LOW | Ash.Type.CiString validates length and match constraints before case folding, allowing con |
| CVE-2026-82734 | 2.1 LOW | Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal |
| CVE-2026-82743 | 2.1 LOW | Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet