Ash Project
63 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-74837
HIGH 8.7
Ash Typescript — Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an una…● PoC
2026-09-01
CVE-2026-77856
HIGH 8.2
Ash Typescript — Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an una…● PoC
2026-09-01
CVE-2026-77950
MEDIUM 6.3
Ash Typescript — Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allow…● PoC
2026-09-01
CVE-2026-82730
HIGH 8.2
Ash Typescript — Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read …● PoC
2026-09-01
CVE-2026-82731
LOW 2.3
Ash Typescript — URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an atta…● PoC
2026-09-01
CVE-2026-82732
MEDIUM 6.3
Ash Typescript — Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argum…● PoC
2026-09-01
CVE-2026-82733
MEDIUM 6.3
Ash Typescript — Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allow…● PoC
2026-09-01
CVE-2026-82734
LOW 2.1
Ash — Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to subm…● PoC
2026-09-01
CVE-2026-82735
MEDIUM 5.9
Ash — Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to force an expensive re…● PoC
2026-09-01
CVE-2026-82736
LOW 2.1
Ash — Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store…● PoC
2026-09-01
CVE-2026-82737
MEDIUM 5.9
Ash — Integer Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored vector and c…● PoC
2026-09-01
CVE-2026-82738
MEDIUM 5.9
Ash — Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a …● PoC
2026-09-01
CVE-2026-82739
LOW 2.1
Ash — Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the st…● PoC
2026-09-01
CVE-2026-82740
LOW 2.1
Ash — Improper Input Validation vulnerability in ash-project ash fails to enforce the outer array constraints on a d…● PoC
2026-09-01
CVE-2026-82741
LOW 2.1
Ash — Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the s…● PoC
2026-09-01
CVE-2026-82742
MEDIUM 5.9
Ash — Uncontrolled Resource Consumption vulnerability in ash-project ash lets an attacker exhaust node memory by mat…
2026-09-01
CVE-2026-82743
LOW 2.1
Ash — Uncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spin a schedu…● PoC
2026-09-01
CVE-2026-82744
LOW 2.1
Ash — Not Failing Securely (Failing Open) vulnerability in ash-project ash skips an Ash.Reactor change when the guar…● PoC
2026-09-01
CVE-2026-82745
MEDIUM 5.9
Ash — Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record whe…● PoC
2026-09-01
CVE-2026-82746
MEDIUM 5.9
Ash — Missing Authorization vulnerability in ash-project ash allows an actor to update records forbidden by resource…● PoC
2026-09-01
CVE-2026-82747
MEDIUM 5.9
Ash — Incorrect Authorization vulnerability in ash-project ash returns records that a runtime read policy denies to …● PoC
2026-09-01
CVE-2026-82748
LOW 2.1
Ash — Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while c…● PoC
2026-09-01
CVE-2026-82749
MEDIUM 5.9
Ash — Incorrect Authorization vulnerability in ash-project ash widens a relationship's parent(...) scoping filter to…● PoC
2026-09-01
CVE-2026-75757
HIGH 8.3
Ash Admin — Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an a…● PoC
2026-08-31
CVE-2026-75760
HIGH 7.1
Ash Ai — Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses pro…● PoC
2026-08-31
CVE-2026-77850
HIGH 8.4
Ash Admin — Stored Cross-site Scripting vulnerability in ash-project ash_admin executes attacker-supplied record content a…● PoC
2026-08-31
CVE-2026-77956
HIGH 8.9
Ash Ai — Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, u…● PoC
2026-08-31
CVE-2026-81315
HIGH 7.4
Ash Ai — Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP serv…● PoC
2026-08-31
CVE-2026-81852
LOW 2.1
Ash Admin — Use of Insufficiently Random Values vulnerability in ash-project ash_admin ships a hardcoded, publicly known C…● PoC
2026-08-31
CVE-2026-81853
LOW 2.3
Ash Admin — Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_admin turns a record-lookup …● PoC
2026-08-31
CVE-2026-82564
HIGH 7.1
Ash Ai — Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an ide…● PoC
2026-08-31
CVE-2026-82579
MEDIUM 6
Ash Ai — Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker wh…● PoC
2026-08-31
CVE-2026-82580
MEDIUM 5.3
Ash Ai — Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses int…● PoC
2026-08-31
CVE-2026-82673
HIGH 8.3
Ash Admin — Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in ash-project ash_…● PoC
2026-08-31
CVE-2026-82681
LOW 2
Ash Admin — Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a…● PoC
2026-08-31
CVE-2026-82722
HIGH 8.3
Ash Admin — Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_admin lets any client th…● PoC
2026-08-31
CVE-2026-82724
HIGH 7.6
Ash Phoenix — Incorrect Authorization vulnerability in ash-project ash_phoenix invokes the SubdomainHook authorization callb…● PoC
2026-08-31
CVE-2026-82725
LOW 2.3
Ash Phoenix — Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_phoenix lets an attacker who…● PoC
2026-08-31
CVE-2026-82726
MEDIUM 6.3
Ash Phoenix — Permissive Regular Expression vulnerability in ash-project ash_phoenix lets a remote client select the tenant …● PoC
2026-08-31
CVE-2026-82727
LOW 2.3
Ash Phoenix — Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_phoenix writes t…● PoC
2026-08-31
CVE-2026-75847
MEDIUM 5.9
Ash Paper Trail — Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker wit…● PoC
2026-08-30
CVE-2026-77454
MEDIUM 5.9
Ash Sql — Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorizat…● PoC
2026-08-30
CVE-2026-77831
LOW 2.1
Ash Paper Trail — Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a…● PoC
2026-08-30
CVE-2026-77846
LOW 2.1
Ash Sqlite — Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows…● PoC
2026-08-30
CVE-2026-77970
MEDIUM 5.9
Ash Paper Trail — Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker wit…● PoC
2026-08-30
CVE-2026-78038
MEDIUM 5.9
Ash Oban — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project as…● PoC
2026-08-30
CVE-2026-78228
MEDIUM 5.9
Ash Oban — Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error …● PoC
2026-08-30
CVE-2026-78691
LOW 2.1
Ash Sql — Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a …● PoC
2026-08-30
CVE-2026-78693
MEDIUM 6.9
Ash Graphql — Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_graphql allows a…● PoC
2026-08-30
CVE-2026-78699
HIGH 7.2
Ash Postgres — Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename t…● PoC
2026-08-30
CVE-2026-80223
HIGH 7.1
Ash Graphql — Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one ten…● PoC
2026-08-30
CVE-2026-80227
LOW 2.1
Ash Sql — Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newlin…● PoC
2026-08-30
CVE-2026-81316
LOW 2.1
Ash Sql — Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value com…● PoC
2026-08-30
CVE-2026-81318
LOW 2.1
Ash Sql — Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant app…● PoC
2026-08-30
CVE-2026-81319
MEDIUM 5.9
Ash Cloak — Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence …● PoC
2026-08-30
CVE-2026-81322
LOW 2.1
Ash Cloak — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyon…● PoC
2026-08-30
CVE-2026-81633
MEDIUM 6.9
Ash Graphql — Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a…● PoC
2026-08-30
CVE-2026-81636
HIGH 8.7
Ash Graphql — Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauth…● PoC
2026-08-30
CVE-2026-81643
LOW 2.3
Ash Graphql — Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for re…● PoC
2026-08-30
CVE-2026-82367
LOW 2.3
Ash Graphql — Exposure of Data Element to Wrong Session vulnerability in ash-project ash_graphql can deliver one subscriptio…● PoC
2026-08-30
CVE-2026-67579
HIGH 7.5
Ash — Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to injec…● PoC
2026-08-12
CVE-2026-69659
MEDIUM 5.9
Ash — Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of…● PoC
2026-08-09
CVE-2026-70395
LOW 2.1
Ash — Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an att…
2026-08-09