Resource Allocation Vulnerability in Ash-Admin by Ash-Project
CVE-2026-82722
What is CVE-2026-82722?
The Ash-Admin component of Ash-Project contains a vulnerability that allows clients to overload the BEAM atom table, potentially crashing the entire node. This is caused by two LiveView event handlers that handle user input without sufficient validation. Specifically, unvalidated atoms are created through inputs from clients, leading to exhaustion of the atom table and subsequent denial of service. Mitigation has been implemented in versions 1.3.1 and above, ensuring that submitted resource and domain strings are validated against known resources, preventing uncontrolled creation of atoms.
Affected Version(s)
ash_admin 0.1.0 < 1.3.1
ash_admin 98b03baa8422b94dd13e305bf08b8ee3f7232c7b < 731dffa09416d68f4ad3a0b6ee146b285ca0083b
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
