CVE Tools

Ash-project

77 CVEs tracked since 2026. Since Aug 2026, none of them reached CISA KEV.

Ash-project CVEs per month

Aug 2026 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Ash-project CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-08400
2026-09370

Products

The products that kept showing up in Ash-project's monthly top three, with their CVEs summed over those months.

  1. Ash181 month
  2. Ash_admin71 month
  3. Ash_typescript71 month
  4. Ash_ai61 month
  5. Ash_authentication_oauth2_server61 month
  6. Ash_graphql61 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Ash-project.

  1. CVE-2026-93477Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash—
  2. CVE-2026-86338Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle—
  3. CVE-2026-78216AshLua eval read operations can read field-policy-protected fields via aggregates—
  4. CVE-2026-78230AshAi aggregate tool can read field-policy-protected fields—
  5. CVE-2026-82710Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadata—
  6. CVE-2026-82584Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata—
  7. CVE-2026-82586AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes—
  8. CVE-2026-81638Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry—
  9. CVE-2026-82758ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint—
  10. CVE-2026-82757ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF—
  11. CVE-2026-82756ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection—
  12. CVE-2026-82755ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion—
  13. CVE-2026-82754ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls—
  14. CVE-2026-82753Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server—
  15. CVE-2026-82752Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length—

The record

Peak rank
#27 in Sep 2026
Busiest month shown
Aug 2026, 40 CVEs
Months with a KEV entry
0 since Aug 2026
Monthly snapshots
2 since 2026
Ash-project's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store