Improper Input Validation in Ash Framework by Ash Project
CVE-2026-82734

2.1LOW

Key Information:

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-82734?

A flaw in the Ash Framework allows attackers to submit non-finite decimal values, bypassing numeric bounds constraints. This occurs in the decimal casting operations, where values like 'Infinity' or 'NaN' can be processed without proper validation. Such inputs lead to failures during arithmetic operations and cause disruptions in further data handling. The vulnerability is addressed in subsequent versions, rejecting non-finite Decimal inputs during the casting process.

Affected Version(s)

ash 1.28.0 < 3.32.2

ash db6bdfcf1518c70d67975efb140cdeb2cb6a76e7 < 818087b1b3364f2af6f5460d6b01262ad0f69204

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonatan Männchen / EEF
Zach Daniel / Ash Project
Peter Ullrich
Peter Ullrich
.