Vulnerabilidades en ash-project

84 resultados
Análisis Vexday

Ash Project apresenta um perfil de risco baixo com apenas 7 CVEs catalogadas, nenhuma atualmente sob exploração ativa. A vulnerabilidade dominante é CWE-863 (Uso Impróprio de Autorização), sem críticas de severidade máxima registradas. O risco é moderado dado 1 publicação nos últimos 90 dias, indicando manutenção ativa do projeto.

CVE-2026-78216MEDIUMAshLua eval read operations can read field-policy-protected fields via aggregatesEPSS 0.4%CVE-2026-86338MEDIUMAsh field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracleEPSS 0.4%CVE-2026-81643LOWBroken access control in AshGraphql subscription batcher applies authorization suppression to only the first notificationEPSS 0.4%CVE-2026-82367LOWRe-entrant synchronous publish in AshGraphql subscription batcher delivers one subscriber's records to another's topicEPSS 0.4%CVE-2025-48043HIGHBypass and runtime policies that can never pass may be incorrectly applied in filter authorizationEPSS 0.4%CVE-2026-78038MEDIUMJob argument injection via :args overrides primary_key and tenant in AshObanEPSS 0.4%CVE-2026-81319MEDIUMUnsafe deserialization of decrypted terms enables node DoS in AshCloakEPSS 0.4%CVE-2026-55736MEDIUMPrivate action arguments can be set by user input in AshEPSS 0.4%CVE-2026-80227LOWSQL string_trim removes only spaces, diverging from in-memory trimming in AshSqlEPSS 0.4%CVE-2026-69659MEDIUMMemory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.KeysetEPSS 0.4%CVE-2025-48042HIGHBefore action hooks may execute in certain scenarios despite a request being forbiddenEPSS 0.3%CVE-2026-77956HIGHEEx template evaluation of prompt content in AshAi enables remote code executionEPSS 0.3%CVE-2026-81315HIGHMCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto headerEPSS 0.3%CVE-2026-77846LOWJSON path injection via unescaped get_path segments in AshSqliteEPSS 0.2%CVE-2026-70395LOWPredicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in AshEPSS 0.2%CVE-2026-78691LOWUnescaped backslash allows LIKE wildcard injection in AshSql string searchEPSS 0.2%CVE-2026-82734LOWNon-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.DecimalEPSS 0.2%CVE-2026-82741LOWAsh.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusionEPSS 0.2%CVE-2026-82744LOWAsh.Reactor change step fails open, skipping a change when its where guard raisesEPSS 0.2%CVE-2026-81638LOWNon-canonical ULID spellings are accepted and alias to the same record in ash_double_entryEPSS 0.2%