← All credits
Zach Daniel / Ash Project
69 vulnerability records and advisories credit this contributor.
CVE-2026-94201
Filtering an :atom attribute with unsafe_to_atom? can exhaust the BEAM atom table in Ash
CVE-2026-82584
Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata
CVE-2026-93477
Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash
CVE-2026-86338
Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle
CVE-2026-78230
AshAi aggregate tool can read field-policy-protected fields
CVE-2026-78216
AshLua eval read operations can read field-policy-protected fields via aggregates
CVE-2026-82752
Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length
CVE-2026-82758
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
CVE-2026-82757
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
CVE-2026-82756
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection