ash_graphql
Hex6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ash_graphqlpage 1 of 1
- CVE-2026-78693MEDIUMCVSS 6.9EG 6.9✓ Fixed in 1.11.02026-08-30
vulnerable: 1.10.0 ... 1.9.4 (7 versions)
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_graphql allows a remote client to read internal field names that an application configured its error_handler to redact. In AshGraphql.Errors, ea…
- CVE-2026-80223HIGHCVSS 7.1EG 7.1✓ Fixed in 1.11.02026-08-30
vulnerable: 1.10.0 ... 1.9.4 (42 versions)
Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive another tenant's records over GraphQL subscriptions. The subscription resolver in AshGraphql.Graphql.Resolver aut…
- CVE-2026-81633MEDIUMCVSS 6.9EG 6.9✓ Fixed in 1.11.02026-08-30
vulnerable: 0.27.0 ... 1.9.4 (63 versions)
Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a relay node(id: ...) query with an unhandled KeyError. AshGraphql.Graphql.Resolver.resolve_node/2 decodes the client-supplied gl…
- CVE-2026-81636HIGHCVSS 8.7EG 8.7✓ Fixed in 1.11.02026-08-30
vulnerable: 0.16.23 ... 1.9.4 (128 versions)
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated client to bypass the configured GraphQL query-complexity limit and force an unbounded database read. AshGraphql.Graphq…
- CVE-2026-81643LOWCVSS 2.3EG 2.3✓ Fixed in 1.11.02026-08-30
vulnerable: 1.10.0 ... 1.9.4 (42 versions)
Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a subscriber is not authorized to see. In AshGraphql.Subscription.Batcher, do_send/5 resolves the first notification of a …
- CVE-2026-82367LOWCVSS 2.3EG 2.3✓ Fixed in 1.11.02026-08-30
vulnerable: 1.10.0 ... 1.9.4 (42 versions)
Exposure of Data Element to Wrong Session vulnerability in ash-project ash_graphql can deliver one subscription's resolved records to a different subscriber's topic. AshGraphql.Subscription.Batcher.do_send/5 reads the resolved batch from …
Check whether ash_graphql is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ash_graphql CVEs against the assets you own.
Start Free Scan →