Failing Open Vulnerability in ash-project's Ash Framework
CVE-2026-82744
2.1LOW
What is CVE-2026-82744?
A failing open vulnerability in the Ash Framework allows security-relevant changes to be bypassed when validations raise exceptions on attacker-influenced input. This occurs because the Ash.Reactor.ChangeStep improperly treats raised exceptions, enabling attackers to exploit this flaw and undermine expected security protocols. As a result, modifications intended to enforce security measures may not be executed, allowing possible breaches. Developers are advised to update to versions 3.32.2 and above to mitigate this issue.
Affected Version(s)
ash 3.0.0-rc.17 < 3.32.2
ash 321f43bd05ad9544e693cbf797243693e51a6be4 < 6d2eb86ea8d2ba5ffac89c1b8b9bf46e331feabc
References
CVSS V4
Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Peter Ullrich
Jonatan Männchen / EEF
Zach Daniel / Ash Project
Peter Ullrich
