Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-86338— Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle

Quick assessment

Affected
ash-project ash
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述信息的中文翻译: Ash 的字段策略(field policies)旨在防范基于过滤器的信息泄露:当某个执行者(actor)无权查看的字段在过滤器中被引用时,该字段会被替换为一个求值为 nil 的表达式,从而确保过滤器无法被用作“是/否”预言机(oracle),来推断执行者无权查看的字段值。 然而,这种将值置为 nil 的处理仅应用于属性(attributes),而未应用于计算字段(calculations)或聚合字段(aggregates)。用户提供的、引用计算字段或聚合字段的过滤器,其中携带的是

CVSS 6.0 · Medium EPSS 0.43% · P35

Affected Version Matrix 2

VendorProduct Version RangeStatus
ash-project ash 2.11.0-rc.0< 3.33.4 affected
0b6d93c7c4637280b46ae66ea1d2eaf013701238< b3d4503241f3deacb5ceb955e10a4fa927da0f67 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86338

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle
Source: CVE Program / CVE List V5
Vulnerability Description
Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see is referenced in a filter, it is replaced with an expression that evaluates to nil, so a filter cannot be used as a yes/no oracle to read a value the actor cannot see. This nilling was applied to attributes but not to calculations or aggregates. A user-supplied filter reference to a calculation or aggregate carries an Ash.Query.Calculation / Ash.Query.Aggregate struct, which the authorizer's reference replacement did not match (it only matched the Ash.Resource.* structs), so the filter ran against the real value. As a result, an actor whose field policies forbid a calculation or aggregate can still filter by it (for example filter(secret_calc == "x") or filter(comment_count == n)) and learn the value from whether rows match — an oracle that recovers field-policy-protected values one probe at a time. Filtering is commonly exposed to lower-privileged actors (for example via AshGraphql or AshJsonApi filter arguments), which is exactly the surface field policies are meant to protect. The fix routes filter references to calculations and aggregates through the same field-policy nilling as attributes. This issue affects ash: from 2.11.0-rc.0 before 3.33.4.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1220
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ash-project ash 2.11.0-rc.0 ~ 3.33.4 cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
ash-project ash 0b6d93c7c4637280b46ae66ea1d2eaf013701238 ~ b3d4503241f3deacb5ceb955e10a4fa927da0f67 cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-86338

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86338

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-86338 (1)

Other References for CVE-2026-86338 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-86338

No comments yet


Leave a comment