Vulnerabilities in ash-project

83 results
Vexday analysis

Ash Project apresenta um perfil de risco baixo com apenas 7 CVEs catalogadas, nenhuma atualmente sob exploração ativa. A vulnerabilidade dominante é CWE-863 (Uso Impróprio de Autorização), sem críticas de severidade máxima registradas. O risco é moderado dado 1 publicação nos últimos 90 dias, indicando manutenção ativa do projeto.

CVE-2026-82725LOWAshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related dataEPSS 0.3%CVE-2026-80227LOWSQL string_trim removes only spaces, diverging from in-memory trimming in AshSqlEPSS 0.3%CVE-2026-78230MEDIUMAshAi aggregate tool can read field-policy-protected fieldsEPSS 0.2%CVE-2026-80223HIGHCross-tenant subscription disclosure in AshGraphql authorizes notifications in memory without a tenant-scoped readEPSS 0.2%CVE-2026-82724HIGHBroken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomainEPSS 0.2%CVE-2026-78216MEDIUMAshLua eval read operations can read field-policy-protected fields via aggregatesEPSS 0.2%CVE-2026-81643LOWBroken access control in AshGraphql subscription batcher applies authorization suppression to only the first notificationEPSS 0.2%CVE-2026-82367LOWRe-entrant synchronous publish in AshGraphql subscription batcher delivers one subscriber's records to another's topicEPSS 0.2%CVE-2026-81319MEDIUMUnsafe deserialization of decrypted terms enables node DoS in AshCloakEPSS 0.2%CVE-2026-77956HIGHEEx template evaluation of prompt content in AshAi enables remote code executionEPSS 0.2%CVE-2026-81315HIGHMCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto headerEPSS 0.2%CVE-2026-78038MEDIUMJob argument injection via :args overrides primary_key and tenant in AshObanEPSS 0.1%CVE-2026-77846LOWJSON path injection via unescaped get_path segments in AshSqliteEPSS 0.1%CVE-2026-77831LOWAlgorithmic-complexity denial of service in AshPaperTrail full-diff list trackingEPSS 0.1%CVE-2026-70395LOWPredicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in AshEPSS 0.1%CVE-2026-82736LOWAsh.Type.CiString validates length and match constraints before case folding, allowing constraint bypassEPSS 0.1%CVE-2026-82737MEDIUMAsh.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing readsEPSS 0.1%CVE-2026-82735MEDIUMMatch regex runs on over-length input in Ash.Type.String, enabling regex denial of serviceEPSS 0.1%CVE-2026-78691LOWUnescaped backslash allows LIKE wildcard injection in AshSql string searchEPSS 0.1%CVE-2026-82738MEDIUMAsh.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of serviceEPSS 0.1%