ash-project
OSS Librariesoss-project
Latest CVEs
The 15 most recently published vulnerabilities affecting ash-project.
- CVE-2026-86338Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle
- CVE-2026-78216AshLua eval read operations can read field-policy-protected fields via aggregates
- CVE-2026-78230AshAi aggregate tool can read field-policy-protected fields
- CVE-2026-82710Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadata
- CVE-2026-82584Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata
- CVE-2026-82586AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
- CVE-2026-81638Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
- CVE-2026-82758ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
- CVE-2026-82757ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
- CVE-2026-82756ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
- CVE-2026-82755ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
- CVE-2026-82754ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
- CVE-2026-82753Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
- CVE-2026-82752Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length
- CVE-2026-82747Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor