All 5 CVE vulnerabilities found in ash_sql, with AI-generated Chinese analysis, references, and POCs.
Vendor: ash-project
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-77454 | exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql CWE-863 | 5.9 | Medium | 2026-08-30 |
| CVE-2026-81316 | Same-named aggregates with differing filters are conflated in AshSql CWE-863 | 2.1 | Low | 2026-08-30 |
| CVE-2026-81318 | Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql CWE-863 | 2.1 | Low | 2026-08-30 |
| CVE-2026-78691 | Unescaped backslash allows LIKE wildcard injection in AshSql string search CWE-943 | 2.1 | Low | 2026-08-30 |
| CVE-2026-80227 | SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql CWE-697 | 2.1 | Low | 2026-08-30 |
All 5 known CVE vulnerabilities affecting ash_sql with full Chinese analysis, references, and POCs where available.