Inefficient Algorithmic Complexity in ash_paper_trail from Ash Project
CVE-2026-77831

2.1LOW

Key Information:

Vendor
CVE Published:
30 August 2026

What is CVE-2026-77831?

The ash_paper_trail product from Ash Project suffers from an algorithmic inefficiency vulnerability. This allows an attacker to submit a large array attribute during create or update actions, which can trigger a denial of service by causing excessive CPU and memory consumption. Specifically, the full-diff change tracking method results in a cubic scaling of resource use as it repeatedly rebuilds accumulators for each element of the array, leading to significant slowdowns and potential service downtime.

Affected Version(s)

ash_paper_trail 0.1.1 < 0.7.0

ash_paper_trail 449cd2a93416853066378fa61c715e89f80dc854

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.