Input Validation Issue in Ash Project Affects Multiple Versions
CVE-2026-82741

2.1LOW

Key Information:

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-82741?

This vulnerability in the Ash Project allows an attacker to exploit improper validation of input types within Ash.Type.Union data structures. By manipulating the tag names in stored values, an attacker can bypass critical validation and access or mutate data improperly. This can lead to unauthorized access and execution of malicious code under the guise of valid operations. The flaw stems from the union's inability to enforce the correct configured tag during data serialization—thus, delivering a significant security risk that was addressed in version updates.

Affected Version(s)

ash 2.14.18 < 3.32.2

ash b0bd2d23d979e731610327636f51da4981fcef68 < 8dbdaecd0f115f52e7c3f9a3e798617d6fbf5f7d

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zach Daniel / Ash Project
Jonatan Männchen / EEF
Peter Ullrich
Peter Ullrich
.