Denial of Service Vulnerability in Ash Framework by Ash Project
CVE-2026-94201

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-94201?

A vulnerability exists in the Ash Framework where atom-typed attributes are stored and compared as strings. This improper handling allows an attacker to supply crafted strings during filtering, coercing these inputs through Ash.Type.Atom without the necessary coercion callbacks. Consequently, this can lead to the internment of unique atoms for every distinct input value, which is particularly problematic as atoms are not garbage collected in the BEAM system. If an attacker can manipulate filter values for public filterable attributes set with an unsafe_to_atom constraint, they can exhaust the atom table, causing a denial of service condition by crashing the node. Affected versions include Ash Framework from 3.5.1 to 3.34.3, with particular attention to the AshPaperTrail version_action_name attribute that is exposed by default.

Affected Version(s)

ash 3.5.1 < 3.34.3

ash 2970ba3bd5d36d6ad04c731ac87385375d457147 < 5282f3f513053628cdd1bf2236ea22d975d934d4

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Quinn Wilton
Quinn Wilton
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.