Uncontrolled Recursion in ash_oban Affects ash-project
CVE-2026-78228

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-78228?

The vulnerability in ash_oban allows an attacker utilizing the on_error action to trigger an uncontrolled recursion scenario. This leads to the exhaustion of CPU and memory resources as the system continuously re-attempts the failed job without an exit condition. Each failure retains a stack trace, resulting in significant resource consumption and ultimately denying service availability. The affected versions of ash_oban are from 0.8.0-rc.1 to 0.8.14, emphasizing the need for timely patching and upgrades.

Affected Version(s)

ash_oban 0.8.0-rc.1 < 0.8.14

ash_oban 5d117ed2006df7277561c69dbfd39281da6ace9f < 851cd0e76ed882bf736fc48d10f96d037e26b5f0

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.