Integer Overflow Vulnerability in Ash Project for Elixir by Ash-Project
CVE-2026-82737
5.9MEDIUM
What is CVE-2026-82737?
The vulnerability exists due to improper validation of input dimensions in Ash Project's vector handling. When an attacker submits a vector exceeding 65,535 elements, it triggers a wraparound issue in the dimension count. This flaw allows the attacker to corrupt stored vectors, ultimately causing any subsequent reads of the affected data to misparse. As a result, access to the corrupted records is denied, leading to potential disruptions and data integrity concerns. The issue has been addressed by implementing a check to reject vectors with dimensions exceeding the maximum allowed size.
Affected Version(s)
ash 2.14.13 < 3.32.2
ash e2855843ca4a9141dcd7f40f47227e13b43f0e00
References
CVSS V4
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jonatan Männchen / EEF
Zach Daniel / Ash Project
Peter Ullrich
Peter Ullrich
