Sensitive Information Exposure in AshPhoenix by Ash Project
CVE-2026-82727

2.3LOW

Key Information:

Vendor
CVE Published:
31 August 2026

What is CVE-2026-82727?

An exposure of sensitive information vulnerability exists in the AshPhoenix framework, where the raw parameters submitted through union form fields are included in error messages. This flaw allows attackers to see sensitive data, such as passwords, in logs or error reports. When invalid types are submitted, the combination of the full parameter map and internal constraints are logged without proper redaction, potentially disclosing sensitive data. As a response, the fix restricts the information displayed in error messages to only highlight the invalid type and valid options, thus mitigating the risk of sensitive data exposure.

Affected Version(s)

ash_phoenix 1.2.17 < 2.3.25

ash_phoenix a3436fcc321e3b34c242cceaf62c3c92bc1a452b < 0c1775c3cf8988f9abd10a8f92315afc5f06f16d

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.