ash 项目中存在“资源消耗不受控”漏洞。攻击者可以通过在内存中匹配跨多个“多对多”(to-many)关系的过滤条件,从而耗尽节点的内存。 具体而言, 在将过滤条件与内存中的记录进行匹配时,会先将该记录展开为其关联行的各种组合。 (位于 )会预先构建过滤条件所涉及的多个“多对多”关系路径的完整笛卡尔积。因此,如果一个记录具有 K 个“多对多”关系,且每个关系平均包含 M 行,则在检查任何谓词之前,系统就会实例化大约 M^K 种场景。因此,当过滤条件或数据集涉及多个较大的“多对多”关系时,内存分配会呈组合式增长,可能
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash | 1.29.0-rc0 ~ 3.32.2 |
cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
|
|
| ash-project | ash | f6f5d194bfc7802bd32e48bf2eabd2d97a0109a4 ~ da07f009e889819ec410fa1f0f12534bfb9e21dd |
cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74837 | 8.7 HIGH | Unbounded atom creation from client-supplied RPC field names in AshTypescript field format |
| CVE-2026-77856 | 8.2 HIGH | Unbounded atom creation from typed struct field names in AshTypescript field selector |
| CVE-2026-82730 | 8.2 HIGH | Authorization-redacted field values disclosed through AshTypescript result normalization |
| CVE-2026-77950 | 6.3 MEDIUM | RPC error handler fails open in AshTypescript, disclosing unredacted errors |
| CVE-2026-82732 | 6.3 MEDIUM | Declared argument constraints not enforced on AshTypescript typed controller routes |
| CVE-2026-82733 | 6.3 MEDIUM | Route handler return value echoed into AshTypescript error response |
| CVE-2026-82737 | 5.9 MEDIUM | Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting |
| CVE-2026-82735 | 5.9 MEDIUM | Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service |
| CVE-2026-82747 | 5.9 MEDIUM | Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor |
| CVE-2026-82738 | 5.9 MEDIUM | Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of |
| CVE-2026-82745 | 5.9 MEDIUM | ETS and Mnesia data layers overwrite an existing record on create instead of enforcing pri |
| CVE-2026-82746 | 5.9 MEDIUM | Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to for |
| CVE-2026-82749 | 5.9 MEDIUM | Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is |
| CVE-2026-82731 | 2.3 LOW | Unescaped path parameters in AshTypescript generated TypeScript client allow request redir |
| CVE-2026-82739 | 2.1 LOW | Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic misma |
| CVE-2026-82740 | 2.1 LOW | Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs |
| CVE-2026-82736 | 2.1 LOW | Ash.Type.CiString validates length and match constraints before case folding, allowing con |
| CVE-2026-82741 | 2.1 LOW | Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion |
| CVE-2026-82734 | 2.1 LOW | Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal |
| CVE-2026-82743 | 2.1 LOW | Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet