Inefficient Algorithmic Complexity in ash_paper_trail from Ash Project
CVE-2026-77831
2.1LOW
What is CVE-2026-77831?
The ash_paper_trail product from Ash Project suffers from an algorithmic inefficiency vulnerability. This allows an attacker to submit a large array attribute during create or update actions, which can trigger a denial of service by causing excessive CPU and memory consumption. Specifically, the full-diff change tracking method results in a cubic scaling of resource use as it repeatedly rebuilds accumulators for each element of the array, leading to significant slowdowns and potential service downtime.
Affected Version(s)
ash_paper_trail 0.1.1 < 0.7.0
ash_paper_trail 449cd2a93416853066378fa61c715e89f80dc854
References
CVSS V4
Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
