ash_sql
Hex5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ash_sqlpage 1 of 1
- CVE-2026-77454MEDIUMCVSS 5.9EG 5.9✓ Fixed in 0.7.12026-08-30
vulnerable: 0.4.1 ... 0.7.0 (22 versions)
Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as exists/2 over a relationship that declares both a limit (or from_many?) and a parent(...)-referencing fil…
- CVE-2026-78691LOWCVSS 2.1EG 2.1✓ Fixed in 0.7.12026-08-30
vulnerable: 0.1.1-rc.10 ... 0.7.0 (147 versions)
Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or string_ends_with/2 to inject live SQL LIKE wildcards, tur…
- CVE-2026-80227LOWCVSS 2.1EG 2.1✓ Fixed in 0.7.12026-08-30
vulnerable: 0.1.1-rc.0 ... 0.7.0 (157 versions)
Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same express…
- CVE-2026-81316LOWCVSS 2.1EG 2.1✓ Fixed in 0.7.12026-08-30
vulnerable: 0.1.1-rc.0 ... 0.7.0 (157 versions)
Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tena…
- CVE-2026-81318LOWCVSS 2.1EG 2.1✓ Fixed in 0.7.12026-08-30
vulnerable: 0.1.1-rc.0 ... 0.7.0 (157 versions)
Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a distinct query, A…
Check whether ash_sql is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ash_sql CVEs against the assets you own.
Start Free Scan →