Sensitive Information Exposure in AshPhoenix by Ash Project
CVE-2026-82727
What is CVE-2026-82727?
An exposure of sensitive information vulnerability exists in the AshPhoenix framework, where the raw parameters submitted through union form fields are included in error messages. This flaw allows attackers to see sensitive data, such as passwords, in logs or error reports. When invalid types are submitted, the combination of the full parameter map and internal constraints are logged without proper redaction, potentially disclosing sensitive data. As a response, the fix restricts the information displayed in error messages to only highlight the invalid type and valid options, thus mitigating the risk of sensitive data exposure.
Affected Version(s)
ash_phoenix 1.2.17 < 2.3.25
ash_phoenix a3436fcc321e3b34c242cceaf62c3c92bc1a452b < 0c1775c3cf8988f9abd10a8f92315afc5f06f16d
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
