Vulnerabilidades en ash-project
83 resultadosAnálisis Vexday
Ash Project apresenta um perfil de risco baixo com apenas 7 CVEs catalogadas, nenhuma atualmente sob exploração ativa. A vulnerabilidade dominante é CWE-863 (Uso Impróprio de Autorização), sem críticas de severidade máxima registradas. O risco é moderado dado 1 publicação nos últimos 90 dias, indicando manutenção ativa do projeto.
CVE-2026-67579HIGHFilter expression injection via forged keyset pagination cursor in AshEPSS 0.8%CVE-2025-48044HIGHAuthorization bypass when bypass policy condition evaluates to trueEPSS 0.8%CVE-2026-82673HIGHPath traversal in AshAdmin file uploads via unsanitized client filenameEPSS 0.6%CVE-2024-49756MEDIUMAshPostgres empty, atomic, non-bulk actions, policy bypass for side-effects vulnerability.EPSS 0.5%CVE-2025-4754LOWMissing Session Revocation on Logout in ash_authentication_phoenixEPSS 0.4%CVE-2026-34593HIGHAsh Framework: Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crashEPSS 0.4%CVE-2026-82710LOWTerminal escape sequence injection in mix usage_rules.search_docs via package documentation metadataEPSS 0.4%CVE-2026-82753HIGHUnauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_serverEPSS 0.4%CVE-2026-82732MEDIUMDeclared argument constraints not enforced on AshTypescript typed controller routesEPSS 0.4%CVE-2026-82754MEDIUMash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controlsEPSS 0.4%CVE-2025-48043HIGHBypass and runtime policies that can never pass may be incorrectly applied in filter authorizationEPSS 0.4%CVE-2026-82758MEDIUMash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpointEPSS 0.4%CVE-2026-82756MEDIUMash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injectionEPSS 0.4%CVE-2026-82757MEDIUMash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRFEPSS 0.4%CVE-2026-82755MEDIUMash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusionEPSS 0.4%CVE-2026-55736MEDIUMPrivate action arguments can be set by user input in AshEPSS 0.4%CVE-2026-81636HIGHQuery-complexity limit bypass via first/last pagination arguments in AshGraphql enables denial of serviceEPSS 0.3%CVE-2026-82586HIGHAshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributesEPSS 0.3%CVE-2025-48042HIGHBefore action hooks may execute in certain scenarios despite a request being forbiddenEPSS 0.3%CVE-2026-74837HIGHUnbounded atom creation from client-supplied RPC field names in AshTypescript field formatterEPSS 0.3%