Deserialization Vulnerability in AshCloak by Ash Project
CVE-2026-81319

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-81319?

A vulnerability exists in AshCloak that allows attackers to manipulate bytes in an encrypted column, potentially crashing the BEAM node. This issue arises when the decryption process fails to adequately safeguard against untrusted data, permitting unbounded atom creation and decompression bomb scenarios. The AshCloak library, which does not implement the :safe option during decoding, results in atoms being interned and never garbage collected from the payload. This condition could lead to the exhaustion of the atom table or significantly inflate the size of compressed payloads. The vulnerability affects versions of AshCloak prior to 0.4.0.

Affected Version(s)

ash_cloak 0.1.0 < 0.4.0

ash_cloak f1595a77fdfa9bfc672f84c2f77feb9e7bf895fc < 1690f0a436efe3e7c11d70d74ff5a8ac0fdf6608

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.