Current section

2 Advisories

Jump to
EEF-CVE-2026-78228 CVE-2026-78228 GHSA-94p7-498r-mrhp

Unbounded handle_error recursion enables denial of service in AshOban triggers

August 30, 2026
CVSS
?
5.9 / 10.0 Medium
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Versions

>= 0.8.0-rc.1 and < 0.8.14
EEF-CVE-2026-78038 CVE-2026-78038 GHSA-gj9p-x393-rf9h

Job argument injection via :args overrides primary_key and tenant in AshOban

August 30, 2026
CVSS
?
5.9 / 10.0 Medium
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Versions

>= 0.2.5 and < 0.8.14

Checksum

Dependency Config

mix.exs

rebar.config

Gleam

erlang.mk

Package Details

Downloads Last 30 days, all versions
0 1K 2K 3K 4K

this version

0

yesterday

797

last 7 days

12 749

all time

456 404

Last Updated

Aug 30, 2026

License

MIT

Build Tools

mix

Publisher

ash-project ash-project