Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-82681 Query-parameter injection in AshAdmin row-action links via unencoded string primary keys L 2.0 2026-08-31
CVE-2026-77850 Stored XSS in AshAdmin relationship typeahead via unescaped label_field content H 8.4 2026-08-31
CVE-2026-82722 AshAdmin LiveView events intern atoms from client input, exhausting the atom table (node DoS) H 8.3 2026-08-31
CVE-2026-75757 AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a sibling subdomain H 8.3 2026-08-31
CVE-2026-75760 AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error H 7.1 2026-08-31
CVE-2026-82580 AshAi echoes raw tool exception messages into the conversation, disclosing internal details M 5.3 2026-08-31
CVE-2026-82579 AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service M 6.0 2026-08-31
CVE-2026-82564 Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records H 7.1 2026-08-31
CVE-2026-81315 MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header H 7.4 2026-08-31
CVE-2026-77956 EEx template evaluation of prompt content in AshAi enables remote code execution H 8.9 2026-08-31
CVE-2026-78693 Incomplete redaction re-attaches the original error path in AshGraphql, leaking internal field names M 6.9 2026-08-30
CVE-2026-80223 Cross-tenant subscription disclosure in AshGraphql authorizes notifications in memory without a tenant-scoped read H 7.1 2026-08-30
CVE-2026-81636 Query-complexity limit bypass via first/last pagination arguments in AshGraphql enables denial of service H 8.7 2026-08-30
CVE-2026-81633 Unhandled KeyError in AshGraphql relay node resolution crashes queries via an unknown type segment M 6.9 2026-08-30
CVE-2026-81643 Broken access control in AshGraphql subscription batcher applies authorization suppression to only the first notification L 2.3 2026-08-30
CVE-2026-82367 Re-entrant synchronous publish in AshGraphql subscription batcher delivers one subscriber's records to another's topic L 2.3 2026-08-30
CVE-2026-81322 Cloaked plaintext leaks through a non-sensitive action argument in AshCloak L 2.1 2026-08-30
CVE-2026-81319 Unsafe deserialization of decrypted terms enables node DoS in AshCloak M 5.9 2026-08-30
CVE-2026-78699 rename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgres H 7.2 2026-08-30
CVE-2026-77454 exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql M 5.9 2026-08-30
CVE-2026-81316 Same-named aggregates with differing filters are conflated in AshSql L 2.1 2026-08-30
CVE-2026-81318 Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql L 2.1 2026-08-30
CVE-2026-78691 Unescaped backslash allows LIKE wildcard injection in AshSql string search L 2.1 2026-08-30
CVE-2026-80227 SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql L 2.1 2026-08-30
CVE-2026-78228 Unbounded handle_error recursion enables denial of service in AshOban triggers M 5.9 2026-08-30
25 per page · 320 CVEs
« Page of 13 »