VulnSea

ash-project has 14 CVEs on record. Disclosure cadence is accelerating: 14 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 14. The median CVSS is 6.2 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-1220 (3). Most affected products: ash_authentication_oauth2_server (6), ash (2), ash_lua (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.2
Publish → KEV
Last 90 days
14 prev 0

Products

  • ash_authentication_oauth2_server 6
  • ash 2
  • ash_lua 2
  • ash_ai 1
  • ash_double_entry 1
  • igniter 1
14
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

ash-project vulnerabilities

CVEs affecting ash-project, newest first. Open any entry for full detail, references, and exploit status.

14 CVEsRSS

CVE-2026-86338Medium· 6.0
6d ago

Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see is referenced in a filter, it is replaced with an expression that evaluates to nil, so a filter cannot be used a…

Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see is referenced in a filter, it is replaced with an expression that evaluates to nil, so a filter cannot be used a…

Sunlitash-project · ashEPSS 0.32%via NVD
CVE-2026-78230Medium· 6.0
2w ago

AshAi exposes Ash read actions to language-model tool calls

AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash field policies …

Sunlitash-project · ash_aiEPSS 0.25%via NVD
CVE-2026-78216Medium· 6.0
2w ago

AshLua exposes Ash read actions to Lua scripts run through an eval action

AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash fi…

Sunlitash-project · ash_luaEPSS 0.25%via NVD
CVE-2026-82710Low· 2.3
2w ago

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output of mix usage_rules.search_docs. mix usage_r…

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output of mix usage_rules.search_docs. mix usage_r…

Sunlitash-project · usage_rulesEPSS 0.40%via NVD
CVE-2026-82758Medium· 6.3
2w ago

Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. resolve_secret…

Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. resolve_secret…

Sunlitash-project · ash_authentication_oauth2_serverEPSS 0.38%via NVD
CVE-2026-82757Medium· 6.3
2w ago

Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses. public_ip?/…

Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses. public_ip?/…

Sunlitash-project · ash_authentication_oauth2_serverEPSS 0.37%via NVD
CVE-2026-82756Medium· 6.3
2w ago

Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. BearerPlu…

Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. BearerPlu…

Sunlitash-project · ash_authentication_oauth2_serverEPSS 0.38%via NVD
CVE-2026-82755Medium· 6.3
2w ago

Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery metadata to another tenant's clients. The RFC 8414 and RFC 9728…

Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery metadata to another tenant's clients. The RFC 8414 and RFC 9728…

Sunlitash-project · ash_authentication_oauth2_serverEPSS 0.37%via NVD
CVE-2026-82754Medium· 6.3
2w ago

Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix. oauth2_ser…

Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix. oauth2_ser…

Sunlitash-project · ash_authentication_oauth2_serverEPSS 0.39%via NVD
CVE-2026-82753High· 8.2
2w ago

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database storage and memory. The /authorize endpoint is unauthenticated by …

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database storage and memory. The /authorize endpoint is unauthenticated by …

Twilightash-project · ash_authentication_oauth2_serverEPSS 0.40%via NVD
CVE-2026-82586High· 8.2
2w ago

Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manife…

Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manife…

Twilightash-project · ash_luaEPSS 0.33%via NVD
CVE-2026-82584Low· 2.3
2w ago

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher to forge the mix igniter.install confirmation prompt. mix igniter.install prints a confirmation pane…

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher to forge the mix igniter.install confirmation prompt. mix igniter.install prints a confirmation pane…

Sunlitash-project · igniterEPSS 0.30%via NVD
CVE-2026-81638Low· 2.1
2w ago

Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier. AshDoubleEntry.ULID renders a 128-bit ULID as 26 Crockford base…

Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier. AshDoubleEntry.ULID renders a 128-bit ULID as 26 Crockford base…

Sunlitash-project · ash_double_entryEPSS 0.13%via NVD
CVE-2026-82752Medium· 5.9PoC
2w ago

Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in an attribute whose length constraint should bound it. Ash measures string length with Elixir's …

Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in an attribute whose length constraint should bound it. Ash measures string length with Elixir's …

Twilightash-project · ashEPSS 0.13%via NVD
ash-project vulnerabilities (CVEs) · VulnSea