Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-82744 Ash.Reactor change step fails open, skipping a change when its where guard raises L 2.1 2026-09-01
CVE-2026-82743 Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads L 2.1 2026-09-01
CVE-2026-82742 Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory M 5.9 2026-09-01
CVE-2026-82741 Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion L 2.1 2026-09-01
CVE-2026-82740 Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs L 2.1 2026-09-01
CVE-2026-82739 Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error L 2.1 2026-09-01
CVE-2026-82738 Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service M 5.9 2026-09-01
CVE-2026-82737 Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads M 5.9 2026-09-01
CVE-2026-82736 Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypass L 2.1 2026-09-01
CVE-2026-82735 Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service M 5.9 2026-09-01
CVE-2026-82734 Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal L 2.1 2026-09-01
CVE-2026-82731 Unescaped path parameters in AshTypescript generated TypeScript client allow request redirection L 2.3 2026-09-01
CVE-2026-74837 Unbounded atom creation from client-supplied RPC field names in AshTypescript field formatter H 8.7 2026-09-01
CVE-2026-82733 Route handler return value echoed into AshTypescript error response M 6.3 2026-09-01
CVE-2026-82732 Declared argument constraints not enforced on AshTypescript typed controller routes M 6.3 2026-09-01
CVE-2026-82730 Authorization-redacted field values disclosed through AshTypescript result normalization H 8.2 2026-09-01
CVE-2026-77950 RPC error handler fails open in AshTypescript, disclosing unredacted errors M 6.3 2026-09-01
CVE-2026-77856 Unbounded atom creation from typed struct field names in AshTypescript field selector H 8.2 2026-09-01
CVE-2026-82725 AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data L 2.3 2026-08-31
CVE-2026-82724 Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain H 7.6 2026-08-31
CVE-2026-82726 AshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary tenant M 6.3 2026-08-31
CVE-2026-82727 AshPhoenix Form.Auto leaks submitted params in an unknown _union_type error message L 2.3 2026-08-31
CVE-2026-82673 Path traversal in AshAdmin file uploads via unsanitized client filename H 8.3 2026-08-31
CVE-2026-81853 AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracle L 2.3 2026-08-31
CVE-2026-81852 AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass L 2.1 2026-08-31
25 per page · 320 CVEs
« Page of 13 »