ash
3.33.3
A declarative, extensible framework for building Elixir applications.
Current section
25 Advisories
Jump to
Current section
25 Advisories
Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-82752.html
- https://github.com/ash-project/ash/commit/a64cab49b8886503e6b7c7b211d83c475aac48ca
- https://github.com/ash-project/ash/commit/cdbf4c4da6bda5f6f139078f01a64320b595216d
- https://github.com/ash-project/ash/security/advisories/GHSA-cwjv-574p-59f6
- https://hex.pm/packages/ash
Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor
Affected Versions
Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records
Affected Versions
Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another
Affected Versions
Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records
Affected Versions
ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness
Affected Versions
Ash.Reactor change step fails open, skipping a change when its where guard raises
Affected Versions
Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads
Affected Versions
Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory
Affected Versions
Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion
Affected Versions
Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs
Affected Versions
Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error
Affected Versions
Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service
Affected Versions
Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads
Affected Versions
Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypass
Affected Versions
Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service
Affected Versions
Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal
Affected Versions
Filter expression injection via forged keyset pagination cursor in Ash
Affected Versions
Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash
Affected Versions
Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset
Affected Versions
Private action arguments can be set by user input in Ash
Affected Versions
Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash
Affected Versions
References
Authorization bypass when bypass policy condition evaluates to true
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2025-48044.html
- https://github.com/ash-project/ash
- https://github.com/ash-project/ash/commit/8b83efa225f657bfc3656ad8ee8485f9b2de923d
- https://github.com/ash-project/ash/security/advisories/GHSA-pcxq-fjp3-r752
- https://hex.pm/packages/ash
- https://nvd.nist.gov/vuln/detail/CVE-2025-48044
- https://osv.dev/vulnerability/EEF-CVE-2025-48044
Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2025-48043.html
- https://github.com/ash-project/ash
- https://github.com/ash-project/ash/commit/66d81300065b970da0d2f4528354835d2418c7ae
- https://github.com/ash-project/ash/releases/tag/v3.6.2
- https://github.com/ash-project/ash/security/advisories/GHSA-7r7f-9xpj-jmr7
- https://hex.pm/packages/ash
- https://nvd.nist.gov/vuln/detail/CVE-2025-48043
- https://osv.dev/vulnerability/EEF-CVE-2025-48043
Before action hooks may execute in certain scenarios despite a request being forbidden
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2025-48042.html
- https://github.com/ash-project/ash
- https://github.com/ash-project/ash/commit/5d1b6a5d00771fd468a509778637527b5218be9a
- https://github.com/ash-project/ash/security/advisories/GHSA-jj4j-x5ww-cwh9
- https://hex.pm/packages/ash
- https://nvd.nist.gov/vuln/detail/CVE-2025-48042
- https://osv.dev/vulnerability/EEF-CVE-2025-48042
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
240
yesterday
4 824
last 7 days
31 293
all time
1 939 888