Vulnerabilities in ash-project

83 results
Vexday analysis

Ash Project apresenta um perfil de risco baixo com apenas 7 CVEs catalogadas, nenhuma atualmente sob exploração ativa. A vulnerabilidade dominante é CWE-863 (Uso Impróprio de Autorização), sem críticas de severidade máxima registradas. O risco é moderado dado 1 publicação nos últimos 90 dias, indicando manutenção ativa do projeto.

CVE-2026-82741LOWAsh.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusionEPSS 0.1%CVE-2026-82744LOWAsh.Reactor change step fails open, skipping a change when its where guard raisesEPSS 0.1%CVE-2026-82734LOWNon-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.DecimalEPSS 0.1%CVE-2026-81638LOWNon-canonical ULID spellings are accepted and alias to the same record in ash_double_entryEPSS 0.1%CVE-2026-69659MEDIUMMemory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.KeysetEPSS 0.1%CVE-2026-77454MEDIUMexists/2 predicate silently dropped on limited relationships with a parent() filter in AshSqlEPSS 0.1%CVE-2026-82742MEDIUMAsh.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memoryEPSS 0.1%CVE-2026-82739LOWAsh.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch errorEPSS 0.1%CVE-2026-78228MEDIUMUnbounded handle_error recursion enables denial of service in AshOban triggersEPSS 0.1%CVE-2026-82743LOWAsh.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async readsEPSS 0.1%CVE-2026-82752MEDIUMAsh string length constraints count graphemes, so a combining-mark string of any size passes max_lengthEPSS 0.1%CVE-2026-82740LOWAsh.Type ignores outer array constraints on nested {:array, {:array, type}} inputsEPSS 0.1%CVE-2026-82745MEDIUMETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniquenessEPSS 0.1%CVE-2026-81316LOWSame-named aggregates with differing filters are conflated in AshSqlEPSS 0.1%CVE-2026-81318LOWDistinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSqlEPSS 0.1%CVE-2026-82749MEDIUMAsh relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped recordsEPSS 0.1%CVE-2026-82747MEDIUMAsh.Policy.Authorizer returns records denied by a runtime read policy to any actorEPSS 0.1%CVE-2026-82746MEDIUMAsh.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden recordsEPSS 0.1%CVE-2026-82748LOWAsh.Actions.Aggregate authorizes an aggregate under one action but computes it under anotherEPSS 0.1%CVE-2026-78699HIGHrename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgresEPSS 0.1%