项目中存在一个“授权不正确”(Incorrect Authorization)漏洞。当关系中的 范围过滤所引用的父级字段无法解析时,该过滤条件会被放宽,从而匹配到本不应包含的记录。 具体而言,加载一个在过滤器中引用了 的关系时,该表达式会针对父记录进行解析。在 (位于 )中,如果父级引用无法解析(例如源查询中未选择所引用的字段),原实现会将其解析为 ,而不是报错。这导致诸如 这样的范围谓词退化为 匹配,而类似 或 的守卫条件会激活其无限制分支,从而使关系返回那些本应被范围排除的记录。修复方案是:当 引用无法解析时,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash | 3.13.2 ~ 3.32.2 |
cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
|
|
| ash-project | ash | 0ddff26e6e6bc6d182e1af2f98b431575e5b4179 ~ e52dad2c39a35f6f043f7324d26e4f4e2551dfd2 |
cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74837 | 8.7 HIGH | Unbounded atom creation from client-supplied RPC field names in AshTypescript field format |
| CVE-2026-77856 | 8.2 HIGH | Unbounded atom creation from typed struct field names in AshTypescript field selector |
| CVE-2026-82730 | 8.2 HIGH | Authorization-redacted field values disclosed through AshTypescript result normalization |
| CVE-2026-77950 | 6.3 MEDIUM | RPC error handler fails open in AshTypescript, disclosing unredacted errors |
| CVE-2026-82732 | 6.3 MEDIUM | Declared argument constraints not enforced on AshTypescript typed controller routes |
| CVE-2026-82733 | 6.3 MEDIUM | Route handler return value echoed into AshTypescript error response |
| CVE-2026-82737 | 5.9 MEDIUM | Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting |
| CVE-2026-82735 | 5.9 MEDIUM | Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service |
| CVE-2026-82747 | 5.9 MEDIUM | Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor |
| CVE-2026-82738 | 5.9 MEDIUM | Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of |
| CVE-2026-82742 | 5.9 MEDIUM | Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, |
| CVE-2026-82745 | 5.9 MEDIUM | ETS and Mnesia data layers overwrite an existing record on create instead of enforcing pri |
| CVE-2026-82746 | 5.9 MEDIUM | Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to for |
| CVE-2026-82731 | 2.3 LOW | Unescaped path parameters in AshTypescript generated TypeScript client allow request redir |
| CVE-2026-82739 | 2.1 LOW | Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic misma |
| CVE-2026-82740 | 2.1 LOW | Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs |
| CVE-2026-82736 | 2.1 LOW | Ash.Type.CiString validates length and match constraints before case folding, allowing con |
| CVE-2026-82741 | 2.1 LOW | Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion |
| CVE-2026-82734 | 2.1 LOW | Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal |
| CVE-2026-82743 | 2.1 LOW | Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet