ash
3.32.0
A declarative, extensible framework for building Elixir applications.
Current section
8 Advisories
Jump to
Current section
8 Advisories
Filter expression injection via forged keyset pagination cursor in Ash
Affected Versions
Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash
Affected Versions
Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset
Affected Versions
Private action arguments can be set by user input in Ash
Affected Versions
Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash
Affected Versions
References
Authorization bypass when bypass policy condition evaluates to true
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2025-48044.html
- https://github.com/ash-project/ash
- https://github.com/ash-project/ash/commit/8b83efa225f657bfc3656ad8ee8485f9b2de923d
- https://github.com/ash-project/ash/security/advisories/GHSA-pcxq-fjp3-r752
- https://hex.pm/packages/ash
- https://nvd.nist.gov/vuln/detail/CVE-2025-48044
- https://osv.dev/vulnerability/EEF-CVE-2025-48044
Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2025-48043.html
- https://github.com/ash-project/ash
- https://github.com/ash-project/ash/commit/66d81300065b970da0d2f4528354835d2418c7ae
- https://github.com/ash-project/ash/releases/tag/v3.6.2
- https://github.com/ash-project/ash/security/advisories/GHSA-7r7f-9xpj-jmr7
- https://hex.pm/packages/ash
- https://nvd.nist.gov/vuln/detail/CVE-2025-48043
- https://osv.dev/vulnerability/EEF-CVE-2025-48043
Before action hooks may execute in certain scenarios despite a request being forbidden
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2025-48042.html
- https://github.com/ash-project/ash
- https://github.com/ash-project/ash/commit/5d1b6a5d00771fd468a509778637527b5218be9a
- https://github.com/ash-project/ash/security/advisories/GHSA-jj4j-x5ww-cwh9
- https://hex.pm/packages/ash
- https://nvd.nist.gov/vuln/detail/CVE-2025-48042
- https://osv.dev/vulnerability/EEF-CVE-2025-48042
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
843
yesterday
4 570
last 7 days
26 707
all time
1 841 027