CVE Tools

Ash

29 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Ash, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Ash CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Ash CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-091
2025-102
2025-110
2025-120
2026-010
2026-020
2026-030
2026-041
2026-050
2026-061
2026-070
2026-083
2026-0919

Severity

How the 29 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical125%
  • High250%
  • Medium125%

Latest CVEs

The 15 most recently published vulnerabilities affecting Ash.

  1. CVE-2026-93477Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash—
  2. CVE-2026-86338Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle—
  3. CVE-2026-82752Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length—
  4. CVE-2026-82747Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor—
  5. CVE-2026-82749Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records—
  6. CVE-2026-82748Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another—
  7. CVE-2026-82746Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records—
  8. CVE-2026-82745ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness—
  9. CVE-2026-82744Ash.Reactor change step fails open, skipping a change when its where guard raises—
  10. CVE-2026-82743Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads—
  11. CVE-2026-82742Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory—
  12. CVE-2026-82741Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion—
  13. CVE-2026-82740Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs—
  14. CVE-2026-82739Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error—
  15. CVE-2026-82738Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store