Ash-project
77 CVEs tracked since 2026. Since Aug 2026, none of them reached CISA KEV.
Ash-project CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-08 | 40 | 0 |
| 2026-09 | 37 | 0 |
Products
The products that kept showing up in Ash-project's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Ash-project.
- CVE-2026-93477Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash—
- CVE-2026-86338Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle—
- CVE-2026-78216AshLua eval read operations can read field-policy-protected fields via aggregates—
- CVE-2026-78230AshAi aggregate tool can read field-policy-protected fields—
- CVE-2026-82710Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadata—
- CVE-2026-82584Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata—
- CVE-2026-82586AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes—
- CVE-2026-81638Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry—
- CVE-2026-82758ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint—
- CVE-2026-82757ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF—
- CVE-2026-82756ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection—
- CVE-2026-82755ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion—
- CVE-2026-82754ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls—
- CVE-2026-82753Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server—
- CVE-2026-82752Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length—
The record
- Peak rank
- #27 in Sep 2026
- Busiest month shown
- Aug 2026, 40 CVEs
- Months with a KEV entry
- 0 since Aug 2026
- Monthly snapshots
- 2 since 2026