Improper Handling of Alternate Encoding in Ash Project's ash_double_entry
CVE-2026-81638
What is CVE-2026-81638?
The ash_double_entry library in the Ash Project is vulnerable to improper handling of alternate encoding. This flaw allows an attacker to manipulate string representations of identifiers, leading to potential data mismanagement. Specifically, the rendering of 128-bit ULIDs as 26 Crockford base-32 characters creates ambiguities, where various representations can resolve to the same value. When these identifiers are exposed through public APIs or HTTP boundaries, it enables attackers to exploit inconsistencies in string handling, potentially bypassing critical checks for idempotency and deduplication. Organizations utilizing affected versions need to apply the recommended patches to mitigate these risks.
Affected Version(s)
ash_double_entry 0.1.0 < 1.0.19
ash_double_entry 1e5f7ce8ff25f519c904731a29eb1258324e561a
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
