Error Message Disclosure Vulnerability in Ash GraphQL by Ash Project
CVE-2026-78693
What is CVE-2026-78693?
A vulnerability in the Ash GraphQL framework allows remote clients to gain access to sensitive internal field names through improperly sanitized error messages. When an application’s error handler is called, it merges the error handling map with the error path, potentially exposing internal names if the error handler fails to properly redact them. This flaw can lead to unauthorized information disclosure, as internal attribute names may leak during validation failures. The issue is evident in Ash GraphQL versions between 1.9.0 and 1.11.0, emphasizing the importance of updating to secure versions.
Affected Version(s)
ash_graphql 1.9.0 < 1.11.0
ash_graphql 6d2d8d995906d68cc245d209a9b3f9853405eb61 < 78e90d369f09f44c534816de541e60841066a467
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
