Deserialization Vulnerability in AshCloak by Ash Project
CVE-2026-81319
What is CVE-2026-81319?
A vulnerability exists in AshCloak that allows attackers to manipulate bytes in an encrypted column, potentially crashing the BEAM node. This issue arises when the decryption process fails to adequately safeguard against untrusted data, permitting unbounded atom creation and decompression bomb scenarios. The AshCloak library, which does not implement the :safe option during decoding, results in atoms being interned and never garbage collected from the payload. This condition could lead to the exhaustion of the atom table or significantly inflate the size of compressed payloads. The vulnerability affects versions of AshCloak prior to 0.4.0.
Affected Version(s)
ash_cloak 0.1.0 < 0.4.0
ash_cloak f1595a77fdfa9bfc672f84c2f77feb9e7bf895fc < 1690f0a436efe3e7c11d70d74ff5a8ac0fdf6608
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
