All 3 CVE vulnerabilities found in ash_paper_trail, with AI-generated Chinese analysis, references, and POCs.
Vendor: ash-project
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-77831 | Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking CWE-407 | 2.1 | Low | 2026-08-30 |
| CVE-2026-77970 | Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions CWE-312 | 5.9 | Medium | 2026-08-30 |
| CVE-2026-75847 | Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail CWE-312 | 5.9 | Medium | 2026-08-30 |
All 3 known CVE vulnerabilities affecting ash_paper_trail with full Chinese analysis, references, and POCs where available.