← Browse

Ash Project

63 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-74837 HIGH 8.7 Ash Typescript — Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an una…● PoC 2026-09-01 CVE-2026-77856 HIGH 8.2 Ash Typescript — Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an una…● PoC 2026-09-01 CVE-2026-77950 MEDIUM 6.3 Ash Typescript — Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allow…● PoC 2026-09-01 CVE-2026-82730 HIGH 8.2 Ash Typescript — Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read …● PoC 2026-09-01 CVE-2026-82731 LOW 2.3 Ash Typescript — URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an atta…● PoC 2026-09-01 CVE-2026-82732 MEDIUM 6.3 Ash Typescript — Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argum…● PoC 2026-09-01 CVE-2026-82733 MEDIUM 6.3 Ash Typescript — Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allow…● PoC 2026-09-01 CVE-2026-82734 LOW 2.1 Ash — Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to subm…● PoC 2026-09-01 CVE-2026-82735 MEDIUM 5.9 Ash — Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to force an expensive re…● PoC 2026-09-01 CVE-2026-82736 LOW 2.1 Ash — Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store…● PoC 2026-09-01 CVE-2026-82737 MEDIUM 5.9 Ash — Integer Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored vector and c…● PoC 2026-09-01 CVE-2026-82738 MEDIUM 5.9 Ash — Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a …● PoC 2026-09-01 CVE-2026-82739 LOW 2.1 Ash — Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the st…● PoC 2026-09-01 CVE-2026-82740 LOW 2.1 Ash — Improper Input Validation vulnerability in ash-project ash fails to enforce the outer array constraints on a d…● PoC 2026-09-01 CVE-2026-82741 LOW 2.1 Ash — Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the s…● PoC 2026-09-01 CVE-2026-82742 MEDIUM 5.9 Ash — Uncontrolled Resource Consumption vulnerability in ash-project ash lets an attacker exhaust node memory by mat… 2026-09-01 CVE-2026-82743 LOW 2.1 Ash — Uncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spin a schedu…● PoC 2026-09-01 CVE-2026-82744 LOW 2.1 Ash — Not Failing Securely (Failing Open) vulnerability in ash-project ash skips an Ash.Reactor change when the guar…● PoC 2026-09-01 CVE-2026-82745 MEDIUM 5.9 Ash — Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record whe…● PoC 2026-09-01 CVE-2026-82746 MEDIUM 5.9 Ash — Missing Authorization vulnerability in ash-project ash allows an actor to update records forbidden by resource…● PoC 2026-09-01 CVE-2026-82747 MEDIUM 5.9 Ash — Incorrect Authorization vulnerability in ash-project ash returns records that a runtime read policy denies to …● PoC 2026-09-01 CVE-2026-82748 LOW 2.1 Ash — Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while c…● PoC 2026-09-01 CVE-2026-82749 MEDIUM 5.9 Ash — Incorrect Authorization vulnerability in ash-project ash widens a relationship's parent(...) scoping filter to…● PoC 2026-09-01 CVE-2026-75757 HIGH 8.3 Ash Admin — Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an a…● PoC 2026-08-31 CVE-2026-75760 HIGH 7.1 Ash Ai — Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses pro…● PoC 2026-08-31 CVE-2026-77850 HIGH 8.4 Ash Admin — Stored Cross-site Scripting vulnerability in ash-project ash_admin executes attacker-supplied record content a…● PoC 2026-08-31 CVE-2026-77956 HIGH 8.9 Ash Ai — Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, u…● PoC 2026-08-31 CVE-2026-81315 HIGH 7.4 Ash Ai — Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP serv…● PoC 2026-08-31 CVE-2026-81852 LOW 2.1 Ash Admin — Use of Insufficiently Random Values vulnerability in ash-project ash_admin ships a hardcoded, publicly known C…● PoC 2026-08-31 CVE-2026-81853 LOW 2.3 Ash Admin — Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_admin turns a record-lookup …● PoC 2026-08-31 CVE-2026-82564 HIGH 7.1 Ash Ai — Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an ide…● PoC 2026-08-31 CVE-2026-82579 MEDIUM 6 Ash Ai — Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker wh…● PoC 2026-08-31 CVE-2026-82580 MEDIUM 5.3 Ash Ai — Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses int…● PoC 2026-08-31 CVE-2026-82673 HIGH 8.3 Ash Admin — Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in ash-project ash_…● PoC 2026-08-31 CVE-2026-82681 LOW 2 Ash Admin — Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a…● PoC 2026-08-31 CVE-2026-82722 HIGH 8.3 Ash Admin — Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_admin lets any client th…● PoC 2026-08-31 CVE-2026-82724 HIGH 7.6 Ash Phoenix — Incorrect Authorization vulnerability in ash-project ash_phoenix invokes the SubdomainHook authorization callb…● PoC 2026-08-31 CVE-2026-82725 LOW 2.3 Ash Phoenix — Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_phoenix lets an attacker who…● PoC 2026-08-31 CVE-2026-82726 MEDIUM 6.3 Ash Phoenix — Permissive Regular Expression vulnerability in ash-project ash_phoenix lets a remote client select the tenant …● PoC 2026-08-31 CVE-2026-82727 LOW 2.3 Ash Phoenix — Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_phoenix writes t…● PoC 2026-08-31 CVE-2026-75847 MEDIUM 5.9 Ash Paper Trail — Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker wit…● PoC 2026-08-30 CVE-2026-77454 MEDIUM 5.9 Ash Sql — Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorizat…● PoC 2026-08-30 CVE-2026-77831 LOW 2.1 Ash Paper Trail — Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a…● PoC 2026-08-30 CVE-2026-77846 LOW 2.1 Ash Sqlite — Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows…● PoC 2026-08-30 CVE-2026-77970 MEDIUM 5.9 Ash Paper Trail — Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker wit…● PoC 2026-08-30 CVE-2026-78038 MEDIUM 5.9 Ash Oban — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project as…● PoC 2026-08-30 CVE-2026-78228 MEDIUM 5.9 Ash Oban — Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error …● PoC 2026-08-30 CVE-2026-78691 LOW 2.1 Ash Sql — Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a …● PoC 2026-08-30 CVE-2026-78693 MEDIUM 6.9 Ash Graphql — Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_graphql allows a…● PoC 2026-08-30 CVE-2026-78699 HIGH 7.2 Ash Postgres — Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename t…● PoC 2026-08-30 CVE-2026-80223 HIGH 7.1 Ash Graphql — Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one ten…● PoC 2026-08-30 CVE-2026-80227 LOW 2.1 Ash Sql — Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newlin…● PoC 2026-08-30 CVE-2026-81316 LOW 2.1 Ash Sql — Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value com…● PoC 2026-08-30 CVE-2026-81318 LOW 2.1 Ash Sql — Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant app…● PoC 2026-08-30 CVE-2026-81319 MEDIUM 5.9 Ash Cloak — Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence …● PoC 2026-08-30 CVE-2026-81322 LOW 2.1 Ash Cloak — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyon…● PoC 2026-08-30 CVE-2026-81633 MEDIUM 6.9 Ash Graphql — Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a…● PoC 2026-08-30 CVE-2026-81636 HIGH 8.7 Ash Graphql — Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauth…● PoC 2026-08-30 CVE-2026-81643 LOW 2.3 Ash Graphql — Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for re…● PoC 2026-08-30 CVE-2026-82367 LOW 2.3 Ash Graphql — Exposure of Data Element to Wrong Session vulnerability in ash-project ash_graphql can deliver one subscriptio…● PoC 2026-08-30 CVE-2026-67579 HIGH 7.5 Ash — Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to injec…● PoC 2026-08-12 CVE-2026-69659 MEDIUM 5.9 Ash — Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of…● PoC 2026-08-09 CVE-2026-70395 LOW 2.1 Ash — Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an att… 2026-08-09