ash_postgres
Hex2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ash_postgrespage 1 of 1
- CVE-2024-49756MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.4.102024-10-23
vulnerable: 2.0.0 ... 2.4.9 (49 versions)
AshPostgres is the PostgreSQL data layer for Ash Framework. Starting in version 2.0.0 and prior to version 2.4.10, in certain very specific situations, it was possible for the policies of an update action to be skipped. This occurred only …
- CVE-2026-78699HIGHCVSS 7.2EG 7.2✓ Fixed in 2.13.02026-08-30
vulnerable: 0.25.0 ... 2.9.1 (374 versions)
Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to have their tenant record repointed at that other tenant's live schema,…
Check whether ash_postgres is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ash_postgres CVEs against the assets you own.
Start Free Scan →