Security: ash-project/ash
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Constraint bypass in `Ash.Type.CiString` in Ash validates before case folding, persisting out-of-bounds valuesGHSA-gg9w-7593-hxg9 published
Sep 1, 2026 by zachdanielLow -
Information disclosure in `Ash.Resource.Validation.Confirm` in Ash leaks a confirmed field via a mismatch errorGHSA-66cg-vj5m-8w7v published
Sep 1, 2026 by zachdanielLow -
Uncontrolled resource consumption in `Ash.Filter.Runtime` in Ash builds a cross-product over to-many relationships in a filterGHSA-mgwj-c69v-6f83 published
Sep 1, 2026 by zachdanielModerate -
Improper input validation in `Ash.Vector` in Ash corrupts vectors over 65,535 elements and crashes on later readsGHSA-68q3-w4w3-2gfv published
Sep 1, 2026 by zachdanielModerate -
Persistent denial of service in `Ash.Type.UUIDv7` in Ash via a stored non-v7 UUID that fails to cast on readGHSA-7xfw-9jwm-9c4c published
Sep 1, 2026 by zachdanielModerate -
Improper input validation in `Ash.Type` in Ash ignores outer constraints on nested `{:array, {:array, type}}` inputsGHSA-v29m-p28g-w5fc published
Sep 1, 2026 by zachdanielLow -
Uncontrolled resource consumption in `Ash.Type.String` in Ash runs match regexes on inputs already rejected for lengthGHSA-mq7g-pffw-m8xh published
Sep 1, 2026 by zachdanielModerate -
Improper input validation in `Ash.Type.Decimal` in Ash accepts Infinity/NaN, bypassing bounds or crashing the requestGHSA-mvvh-q33h-q62v published
Sep 1, 2026 by zachdanielLow -
Fail-open access control in `Ash.Reactor` change steps in Ash skips a gated change when its `where` guard raisesGHSA-3xq4-m876-fr88 published
Sep 1, 2026 by zachdanielLow -
Missing uniqueness check in the Mnesia data layer in Ash lets a create action overwrite an existing recordGHSA-92x7-q3h5-wf88 published
Sep 1, 2026 by zachdanielModerate