Ash
29 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Ash, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Ash CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 1 |
| 2025-10 | 2 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 3 |
| 2026-09 | 19 |
Severity
How the 29 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High2
- Medium1
Latest CVEs
The 15 most recently published vulnerabilities affecting Ash.
- CVE-2026-93477Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash—
- CVE-2026-86338Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle—
- CVE-2026-82752Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length—
- CVE-2026-82747Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor—
- CVE-2026-82749Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records—
- CVE-2026-82748Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another—
- CVE-2026-82746Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records—
- CVE-2026-82745ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness—
- CVE-2026-82744Ash.Reactor change step fails open, skipping a change when its where guard raises—
- CVE-2026-82743Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads—
- CVE-2026-82742Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory—
- CVE-2026-82741Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion—
- CVE-2026-82740Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs—
- CVE-2026-82739Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error—
- CVE-2026-82738Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service—
Product grouping is registry-driven, with AI assist and human review. How it works