ash-project 中 ash 存在不当访问控制(Improper Access Control)漏洞:当使用 ETS 或 Mnesia 数据层时,由于在插入操作中未强制主键唯一性约束,创建(create)操作会覆盖已存在的记录。 与 SQL 数据层不同——SQL 会因主键唯一性约束而拒绝重复主键——ETS 和 Mnesia 数据层将“创建”实现为基于键的插入(keyed insert),会替换任何具有相同主键的现有条目(代码位于 lib/ash/data_layer/ets/ets.ex 和 lib/ash/
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash | 0.4.0 ~ 3.32.2 |
cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
|
|
| ash-project | ash | 6dc699d8a683d542812b34a8c104cc90164add3a ~ 912e243196017c2a812c25905c2b1cc3bbb843fc |
cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74837 | 8.7 HIGH | Unbounded atom creation from client-supplied RPC field names in AshTypescript field format |
| CVE-2026-77856 | 8.2 HIGH | Unbounded atom creation from typed struct field names in AshTypescript field selector |
| CVE-2026-82730 | 8.2 HIGH | Authorization-redacted field values disclosed through AshTypescript result normalization |
| CVE-2026-77950 | 6.3 MEDIUM | RPC error handler fails open in AshTypescript, disclosing unredacted errors |
| CVE-2026-82732 | 6.3 MEDIUM | Declared argument constraints not enforced on AshTypescript typed controller routes |
| CVE-2026-82733 | 6.3 MEDIUM | Route handler return value echoed into AshTypescript error response |
| CVE-2026-82737 | 5.9 MEDIUM | Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting |
| CVE-2026-82735 | 5.9 MEDIUM | Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service |
| CVE-2026-82749 | 5.9 MEDIUM | Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is |
| CVE-2026-82738 | 5.9 MEDIUM | Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of |
| CVE-2026-82742 | 5.9 MEDIUM | Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, |
| CVE-2026-82746 | 5.9 MEDIUM | Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to for |
| CVE-2026-82731 | 2.3 LOW | Unescaped path parameters in AshTypescript generated TypeScript client allow request redir |
| CVE-2026-82739 | 2.1 LOW | Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic misma |
| CVE-2026-82736 | 2.1 LOW | Ash.Type.CiString validates length and match constraints before case folding, allowing con |
| CVE-2026-82740 | 2.1 LOW | Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs |
| CVE-2026-82734 | 2.1 LOW | Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal |
| CVE-2026-82741 | 2.1 LOW | Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion |
| CVE-2026-82743 | 2.1 LOW | Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads |
| CVE-2026-82744 | 2.1 LOW | Ash.Reactor change step fails open, skipping a change when its where guard raises |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet