Uncontrolled Resource Consumption Vulnerability in Ash Project by Ash
CVE-2026-82735
5.9MEDIUM
What is CVE-2026-82735?
The vulnerability in the Ash Project arises from improper handling of regular expression evaluations without adequate constraints. An attacker can leverage this flaw by submitting an input that avoids length limits yet still triggers complex regex processing, leading to excessive CPU consumption and potential Denial of Service (DoS). The issue has been addressed in the recent updates, ensuring regex patterns are only evaluated when input meets length constraints, thus providing improved security and system integrity.
Affected Version(s)
ash 0.10.0 < 3.32.2
ash 05848d5f4affe60fddd812222a18ada080c0813b < 14928412a1a94a69c47df8e98920d3a2b09cdec4
References
CVSS V4
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jonatan Männchen / EEF
Zach Daniel / Ash Project
Peter Ullrich
Peter Ullrich
