All 4 CVE vulnerabilities found in ash_phoenix, with AI-generated Chinese analysis, references, and POCs.
Vendor: ash-project
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-82725 | AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data CWE-639 | 2.3 | Low | 2026-08-31 |
| CVE-2026-82724 | Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain CWE-863 | 7.6 | High | 2026-08-31 |
| CVE-2026-82726 | AshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary tenant CWE-625 | 6.3 | Medium | 2026-08-31 |
| CVE-2026-82727 | AshPhoenix Form.Auto leaks submitted params in an unknown _union_type error message CWE-209 | 2.3 | Low | 2026-08-31 |
All 4 known CVE vulnerabilities affecting ash_phoenix with full Chinese analysis, references, and POCs where available.