Input Validation Issue in Ash Project Affects Multiple Versions
CVE-2026-82741
2.1LOW
What is CVE-2026-82741?
This vulnerability in the Ash Project allows an attacker to exploit improper validation of input types within Ash.Type.Union data structures. By manipulating the tag names in stored values, an attacker can bypass critical validation and access or mutate data improperly. This can lead to unauthorized access and execution of malicious code under the guise of valid operations. The flaw stems from the union's inability to enforce the correct configured tag during data serialization—thus, delivering a significant security risk that was addressed in version updates.
Affected Version(s)
ash 2.14.18 < 3.32.2
ash b0bd2d23d979e731610327636f51da4981fcef68 < 8dbdaecd0f115f52e7c3f9a3e798617d6fbf5f7d
References
CVSS V4
Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zach Daniel / Ash Project
Jonatan Männchen / EEF
Peter Ullrich
Peter Ullrich
