Packages

The extension for building GraphQL APIs with Ash

Current section

6 Advisories

Jump to
EEF-CVE-2026-78693 CVE-2026-78693 GHSA-ppr2-g9h8-w7qp

Incomplete redaction re-attaches the original error path in AshGraphql, leaking internal field names

August 30, 2026
CVSS
?
6.9 / 10.0 Medium
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Versions

>= 1.9.0 and < 1.11.0
EEF-CVE-2026-80223 CVE-2026-80223 GHSA-rcqc-59g2-gjg2

Cross-tenant subscription disclosure in AshGraphql authorizes notifications in memory without a tenant-scoped read

August 30, 2026
CVSS
?
7.1 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Versions

>= 1.4.0 and < 1.11.0
EEF-CVE-2026-81636 CVE-2026-81636 GHSA-mwc4-r9fc-h6mg

Query-complexity limit bypass via first/last pagination arguments in AshGraphql enables denial of service

August 30, 2026
CVSS
?
8.7 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Versions

>= 0.16.23 and < 1.11.0
EEF-CVE-2026-81633 CVE-2026-81633 GHSA-mrgv-g7gf-r96h

Unhandled KeyError in AshGraphql relay node resolution crashes queries via an unknown type segment

August 30, 2026
CVSS
?
6.9 / 10.0 Medium
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Versions

>= 0.27.0 and < 1.11.0
EEF-CVE-2026-81643 CVE-2026-81643 GHSA-j684-hch4-q888

Broken access control in AshGraphql subscription batcher applies authorization suppression to only the first notification

August 30, 2026
EEF-CVE-2026-82367 CVE-2026-82367 GHSA-wm4m-cjmc-5v8c

Re-entrant synchronous publish in AshGraphql subscription batcher delivers one subscriber's records to another's topic

August 30, 2026

Checksum

Dependency Config

mix.exs

rebar.config

Gleam

erlang.mk

Package Details

Downloads Last 30 days, all versions
0 500 1000 1500 2000

this version

0

yesterday

592

last 7 days

6 011

all time

437 529

Last Updated

Aug 30, 2026

License

MIT

Build Tools

mix

Publisher

ash-project ash-project