Improper Input Validation in Ash Project Affects UUID Handling
CVE-2026-82738
5.9MEDIUM
What is CVE-2026-82738?
The Ash Project contains an improper input validation vulnerability that allows an attacker to manipulate UUID attributes, resulting in persistent read errors. By storing non-version-7 UUIDs in an Ash.Type.UUIDv7 attribute, the system fails to retrieve the records associated with these UUIDs. This happens due to the way Ash handles the input and storage of UUIDs, leading to permanent data corruption for the affected records. Users are encouraged to upgrade to the latest version to mitigate this issue.
Affected Version(s)
ash 3.6.3 < 3.32.2
ash 751d8a4d11564efbe358c90c8347f3a00eb60782
References
CVSS V4
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jonatan Männchen / EEF
Zach Daniel / Ash Project
Peter Ullrich
Peter Ullrich
