Improper Handling of Alternate Encoding in Ash Project's ash_double_entry
CVE-2026-81638

2.1LOW

Key Information:

Vendor
CVE Published:
7 September 2026

What is CVE-2026-81638?

The ash_double_entry library in the Ash Project is vulnerable to improper handling of alternate encoding. This flaw allows an attacker to manipulate string representations of identifiers, leading to potential data mismanagement. Specifically, the rendering of 128-bit ULIDs as 26 Crockford base-32 characters creates ambiguities, where various representations can resolve to the same value. When these identifiers are exposed through public APIs or HTTP boundaries, it enables attackers to exploit inconsistencies in string handling, potentially bypassing critical checks for idempotency and deduplication. Organizations utilizing affected versions need to apply the recommended patches to mitigate these risks.

Affected Version(s)

ash_double_entry 0.1.0 < 1.0.19

ash_double_entry 1e5f7ce8ff25f519c904731a29eb1258324e561a

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.