ash
3.24.7
A declarative, extensible framework for building Elixir applications.
Current section
7 Advisories
Jump to
Current section
7 Advisories
Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash
Affected Versions
References
Ash has authorization bypass when bypass policy condition evaluates to true
Affected Versions
References
- https://osv.dev/vulnerability/EEF-CVE-2025-48044
- https://github.com/ash-project/ash/security/advisories/GHSA-pcxq-fjp3-r752
- https://nvd.nist.gov/vuln/detail/CVE-2025-48044
- https://github.com/ash-project/ash/commit/8b83efa225f657bfc3656ad8ee8485f9b2de923d
- https://cna.erlef.org/cves/CVE-2025-48044.html
- https://github.com/ash-project/ash
Authorization bypass when bypass policy condition evaluates to true
Affected Versions
Ash Framework: Filter authorization misapplies impossible bypass/runtime policies
Affected Versions
References
- https://github.com/ash-project/ash/security/advisories/GHSA-7r7f-9xpj-jmr7
- https://nvd.nist.gov/vuln/detail/CVE-2025-48043
- https://github.com/ash-project/ash/commit/66d81300065b970da0d2f4528354835d2418c7ae
- https://cna.erlef.org/cves/CVE-2025-48043.html
- https://github.com/ash-project/ash
- https://github.com/ash-project/ash/releases/tag/v3.6.2
- https://osv.dev/vulnerability/EEF-CVE-2025-48043
Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization
Affected Versions
Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden
Affected Versions
References
- https://osv.dev/vulnerability/EEF-CVE-2025-48042
- https://github.com/ash-project/ash
- https://github.com/ash-project/ash/security/advisories/GHSA-jj4j-x5ww-cwh9
- https://cna.erlef.org/cves/CVE-2025-48042.html
- https://github.com/ash-project/ash/commit/5d1b6a5d00771fd468a509778637527b5218be9a
- https://nvd.nist.gov/vuln/detail/CVE-2025-48042
Before action hooks may execute in certain scenarios despite a request being forbidden
Affected Versions
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
2 488
yesterday
1 137
last 7 days
21 528
all time
1 468 642