Security Advisories
Browse security advisories and track which Dependabot PRs address them.
36,934
Total Advisories
3,439
With Dependabot PRs
4,781
Critical Severity
13,040
High Severity
AshLua eval read operations can read field-policy-protected fields via aggregates
EEF-CVE-2026-78216 GHSA-5whv-8rcp-x33j CVE-2026-78216 MEDIUM 7 days ago
## Summary
AshLua exposes Ash read actions to Lua scripts run through an `eval` action. A read call accepts an `operation` (`list`, `min`, `max`, ...
hex
No PRs yet
AshAi aggregate tool can read field-policy-protected fields
EEF-CVE-2026-78230 GHSA-v5rw-36x5-r5vx CVE-2026-78230 MEDIUM 7 days ago
## Summary
AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (`min`, `max`, `sum`, `avg`...
hex
No PRs yet
Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadata
EEF-CVE-2026-82710 GHSA-j59f-776f-23hp CVE-2026-82710 LOW 7 days ago
## Summary
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publi...
hex
No PRs yet
Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata
EEF-CVE-2026-82584 GHSA-cj7w-j579-gc42 CVE-2026-82584 LOW 7 days ago
## Summary
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher...
hex
No PRs yet
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
EEF-CVE-2026-82586 GHSA-37jv-wc37-fhcw CVE-2026-82586 HIGH 7 days ago
## Summary
Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that ar...
hex
No PRs yet
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
EEF-CVE-2026-81638 GHSA-qxp2-vgp9-268q CVE-2026-81638 LOW 7 days ago
## Summary
Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct str...
hex
No PRs yet
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
EEF-CVE-2026-82758 GHSA-fxc6-vp68-87pw CVE-2026-82758 MEDIUM 7 days ago
## Summary
Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OA...
hex
No PRs yet
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
EEF-CVE-2026-82757 GHSA-wprp-8gvj-p6cv CVE-2026-82757 MEDIUM 7 days ago
## Summary
Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a clie...
hex
No PRs yet
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
EEF-CVE-2026-82756 GHSA-2h3v-83jg-2qmm CVE-2026-82756 MEDIUM 7 days ago
## Summary
Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacke...
hex
No PRs yet
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
EEF-CVE-2026-82755 GHSA-crqf-7m54-4hgc CVE-2026-82755 MEDIUM 7 days ago
## Summary
Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache ...
hex
No PRs yet
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
EEF-CVE-2026-82754 GHSA-wwxg-h779-3wf4 CVE-2026-82754 MEDIUM 7 days ago
## Summary
Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth en...
hex
No PRs yet
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
EEF-CVE-2026-82753 GHSA-9pv3-wxjm-f846 CVE-2026-82753 HIGH 7 days ago
## Summary
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenti...
hex
No PRs yet
Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation
EEF-CVE-2026-82750 GHSA-5qrp-r24c-w6jr CVE-2026-82750 HIGH 9 days ago
## Summary
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's ga...
hex
No PRs yet
Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning
EEF-CVE-2026-82751 GHSA-rpwj-vrf7-4x36 CVE-2026-82751 HIGH 9 days ago
## Summary
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's ga...
hex
No PRs yet
Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length
EEF-CVE-2026-82752 GHSA-cwjv-574p-59f6 CVE-2026-82752 MEDIUM 10 days ago
## Summary
Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary si...
hex
No PRs yet
Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS
EEF-CVE-2026-82728 GHSA-g83f-2j6r-q6m4 CVE-2026-82728 HIGH 11 days ago
## Summary
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on...
hex
1
Dependabot PRs
Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS
EEF-CVE-2026-82729 GHSA-7p8w-j234-7qc8 CVE-2026-82729 MEDIUM 11 days ago
## Summary
Inefficient Algorithmic Complexity vulnerability in elixir-mint mint allows a remote HTTP server to exhaust CPU on the client host and ...
hex
1
Dependabot PRs
Phoenix: Unbounded channel joins per transport enables DoS over few connections
GHSA-6983-jfq8-485w CVE-2026-56811 HIGH 11 days ago
### Summary
Phoenix transports do not limit the number of channels in a given connection, making it easy to spawn hundreds of thousands of process...
hex
No PRs yet
Phoenix: Presence keys colliding with `Object.prototype` members break existence checks
GHSA-63mc-hw7g-86rr CVE-2026-56812 MODERATE 11 days ago
### Summary
The Phoenix JavaScript presence client (`assets/js/phoenix/presence.js`) tests whether a presence already exists using a bare truthine...
hex
npm
No PRs yet
Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor
EEF-CVE-2026-82747 GHSA-4259-gvr2-4xhq CVE-2026-82747 MEDIUM 14 days ago
## Summary
Incorrect Authorization vulnerability in ash-project ash returns records that a runtime read policy denies to any actor.
When a resour...
hex
1
Dependabot PRs
Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records
EEF-CVE-2026-82749 GHSA-j8fx-ff37-4j9c CVE-2026-82749 MEDIUM 14 days ago
## Summary
Incorrect Authorization vulnerability in ash-project ash widens a relationship's `parent(...)` scoping filter to match unintended recor...
hex
1
Dependabot PRs
Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another
EEF-CVE-2026-82748 GHSA-g5hp-mghm-3mgp CVE-2026-82748 LOW 14 days ago
## Summary
Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while computing it under another...
hex
1
Dependabot PRs
Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records
EEF-CVE-2026-82746 GHSA-j7c9-3fw3-jc64 CVE-2026-82746 MEDIUM 14 days ago
## Summary
Missing Authorization vulnerability in ash-project ash allows an actor to update records forbidden by resource policies through the ato...
hex
1
Dependabot PRs
ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness
EEF-CVE-2026-82745 GHSA-92x7-q3h5-wf88 CVE-2026-82745 MEDIUM 14 days ago
## Summary
Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record when the ETS or Mnesia data ...
hex
1
Dependabot PRs
Ash.Reactor change step fails open, skipping a change when its where guard raises
EEF-CVE-2026-82744 GHSA-3xq4-m876-fr88 CVE-2026-82744 LOW 14 days ago
## Summary
Not Failing Securely (Failing Open) vulnerability in ash-project ash skips an `Ash.Reactor` change when the guard controlling it raises...
hex
1
Dependabot PRs
Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads
EEF-CVE-2026-82743 GHSA-33wq-x3q2-c92h CVE-2026-82743 LOW 14 days ago
## Summary
Uncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spin a scheduler thread at full CPU wh...
hex
1
Dependabot PRs
Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory
EEF-CVE-2026-82742 GHSA-mgwj-c69v-6f83 CVE-2026-82742 MEDIUM 14 days ago
## Summary
Uncontrolled Resource Consumption vulnerability in ash-project ash lets an attacker exhaust node memory by matching a filter that spans...
hex
1
Dependabot PRs
Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion
EEF-CVE-2026-82741 GHSA-2mmm-gc86-7jgg CVE-2026-82741 LOW 14 days ago
## Summary
Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the stored type tag of an `Ash...
hex
1
Dependabot PRs
Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs
EEF-CVE-2026-82740 GHSA-v29m-p28g-w5fc CVE-2026-82740 LOW 14 days ago
## Summary
Improper Input Validation vulnerability in ash-project ash fails to enforce the outer array constraints on a doubly-nested `{:array, {:...
hex
1
Dependabot PRs
Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error
EEF-CVE-2026-82739 GHSA-66cg-vj5m-8w7v CVE-2026-82739 LOW 14 days ago
## Summary
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the stored value of a confirmed...
hex
1
Dependabot PRs
Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service
EEF-CVE-2026-82738 GHSA-7xfw-9jwm-9c4c CVE-2026-82738 MEDIUM 14 days ago
## Summary
Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a record by storing a non-v...
hex
1
Dependabot PRs
Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads
EEF-CVE-2026-82737 GHSA-68q3-w4w3-2gfv CVE-2026-82737 MEDIUM 14 days ago
## Summary
Integer Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored vector and crash later reads of it by...
hex
1
Dependabot PRs
Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypass
EEF-CVE-2026-82736 GHSA-gg9w-7593-hxg9 CVE-2026-82736 LOW 14 days ago
## Summary
Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-insensitive strin...
hex
1
Dependabot PRs
Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service
EEF-CVE-2026-82735 GHSA-mq7g-pffw-m8xh CVE-2026-82735 MEDIUM 14 days ago
## Summary
Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to force an expensive regular expression to run o...
hex
1
Dependabot PRs
Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal
EEF-CVE-2026-82734 GHSA-mvvh-q33h-q62v CVE-2026-82734 LOW 14 days ago
## Summary
Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to submit a non-finite decimal v...
hex
1
Dependabot PRs
Unescaped path parameters in AshTypescript generated TypeScript client allow request redirection
EEF-CVE-2026-82731 GHSA-6g23-p936-fm2f CVE-2026-82731 LOW 14 days ago
## Summary
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who controls a path-...
hex
No PRs yet
Unbounded atom creation from client-supplied RPC field names in AshTypescript field formatter
EEF-CVE-2026-74837 GHSA-mhxc-mhqx-3v28 CVE-2026-74837 HIGH 14 days ago
## Summary
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to ...
hex
No PRs yet
Route handler return value echoed into AshTypescript error response
EEF-CVE-2026-82733 GHSA-ghhw-qh7p-55xr CVE-2026-82733 MEDIUM 14 days ago
## Summary
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated atta...
hex
No PRs yet
Declared argument constraints not enforced on AshTypescript typed controller routes
EEF-CVE-2026-82732 GHSA-f7fq-hwq6-jhvv CVE-2026-82732 MEDIUM 14 days ago
## Summary
Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argument values outside a decl...
hex
No PRs yet
Authorization-redacted field values disclosed through AshTypescript result normalization
EEF-CVE-2026-82730 GHSA-6929-rjmh-4x62 CVE-2026-82730 HIGH 14 days ago
## Summary
Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash...
hex
No PRs yet
RPC error handler fails open in AshTypescript, disclosing unredacted errors
EEF-CVE-2026-77950 GHSA-mjr7-r3rf-x963 CVE-2026-77950 MEDIUM 14 days ago
## Summary
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated atta...
hex
No PRs yet
Unbounded atom creation from typed struct field names in AshTypescript field selector
EEF-CVE-2026-77856 GHSA-rj47-h936-4cxw CVE-2026-77856 HIGH 14 days ago
## Summary
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to ...
hex
No PRs yet
AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data
EEF-CVE-2026-82725 GHSA-7xhg-xphm-f458 CVE-2026-82725 LOW 15 days ago
## Summary
Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_phoenix lets an attacker who controls filter form par...
hex
No PRs yet
Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain
EEF-CVE-2026-82724 GHSA-39c8-xcwr-gqff CVE-2026-82724 HIGH 15 days ago
## Summary
Incorrect Authorization vulnerability in ash-project ash_phoenix invokes the `SubdomainHook` authorization callback with a `nil` tenant...
hex
No PRs yet
AshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary tenant
EEF-CVE-2026-82726 GHSA-rpf8-q9jh-qxrr CVE-2026-82726 MEDIUM 15 days ago
## Summary
Permissive Regular Expression vulnerability in ash-project ash_phoenix lets a remote client select the tenant an Ash application uses, ...
hex
No PRs yet
AshPhoenix Form.Auto leaks submitted params in an unknown _union_type error message
EEF-CVE-2026-82727 GHSA-5xf4-hgcq-xw7v CVE-2026-82727 LOW 15 days ago
## Summary
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_phoenix writes the entire raw submitted p...
hex
No PRs yet
Path traversal in AshAdmin file uploads via unsanitized client filename
EEF-CVE-2026-82673 GHSA-483p-rgcq-p5j9 CVE-2026-82673 HIGH 15 days ago
## Summary
Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in ash-project ash_admin allows writing atta...
hex
No PRs yet
AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracle
EEF-CVE-2026-81853 GHSA-jxr8-hpv2-qp38 CVE-2026-81853 LOW 15 days ago
## Summary
Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_admin turns a record-lookup URL into an equality orac...
hex
No PRs yet
AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass
EEF-CVE-2026-81852 GHSA-whfj-rrrp-j597 CVE-2026-81852 LOW 15 days ago
## Summary
Use of Insufficiently Random Values vulnerability in ash-project ash_admin ships a hardcoded, publicly known CSP nonce, defeating nonce...
hex
No PRs yet
Query-parameter injection in AshAdmin row-action links via unencoded string primary keys
EEF-CVE-2026-82681 GHSA-j89q-xjrh-c26p CVE-2026-82681 LOW 15 days ago
## Summary
Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a record's string primary ...
hex
No PRs yet