Denial of Service Vulnerability in Ash Framework by Ash Project
CVE-2026-94201
What is CVE-2026-94201?
A vulnerability exists in the Ash Framework where atom-typed attributes are stored and compared as strings. This improper handling allows an attacker to supply crafted strings during filtering, coercing these inputs through Ash.Type.Atom without the necessary coercion callbacks. Consequently, this can lead to the internment of unique atoms for every distinct input value, which is particularly problematic as atoms are not garbage collected in the BEAM system. If an attacker can manipulate filter values for public filterable attributes set with an unsafe_to_atom constraint, they can exhaust the atom table, causing a denial of service condition by crashing the node. Affected versions include Ash Framework from 3.5.1 to 3.34.3, with particular attention to the AshPaperTrail version_action_name attribute that is exposed by default.
Affected Version(s)
ash 3.5.1 < 3.34.3
ash 2970ba3bd5d36d6ad04c731ac87385375d457147 < 5282f3f513053628cdd1bf2236ea22d975d934d4
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
