Resource Allocation Vulnerability in Ash-Admin by Ash-Project
CVE-2026-82722

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82722?

The Ash-Admin component of Ash-Project contains a vulnerability that allows clients to overload the BEAM atom table, potentially crashing the entire node. This is caused by two LiveView event handlers that handle user input without sufficient validation. Specifically, unvalidated atoms are created through inputs from clients, leading to exhaustion of the atom table and subsequent denial of service. Mitigation has been implemented in versions 1.3.1 and above, ensuring that submitted resource and domain strings are validated against known resources, preventing uncontrolled creation of atoms.

Affected Version(s)

ash_admin 0.1.0 < 1.3.1

ash_admin 98b03baa8422b94dd13e305bf08b8ee3f7232c7b < 731dffa09416d68f4ad3a0b6ee146b285ca0083b

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.