Error Message Disclosure Vulnerability in Ash GraphQL by Ash Project
CVE-2026-78693

6.9MEDIUM

Key Information:

Vendor
CVE Published:
30 August 2026

What is CVE-2026-78693?

A vulnerability in the Ash GraphQL framework allows remote clients to gain access to sensitive internal field names through improperly sanitized error messages. When an application’s error handler is called, it merges the error handling map with the error path, potentially exposing internal names if the error handler fails to properly redact them. This flaw can lead to unauthorized information disclosure, as internal attribute names may leak during validation failures. The issue is evident in Ash GraphQL versions between 1.9.0 and 1.11.0, emphasizing the importance of updating to secure versions.

Affected Version(s)

ash_graphql 1.9.0 < 1.11.0

ash_graphql 6d2d8d995906d68cc245d209a9b3f9853405eb61 < 78e90d369f09f44c534816de541e60841066a467

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.