Executive brief
ash_graphql is a GraphQL library for the Ash framework used to build data APIs. A flaw in its subscription batching mechanism can cause resolved records from one subscription to be incorrectly delivered to a different subscriber's subscription topic, exposing data to the wrong user. This occurs when multiple subscriptions are processed concurrently with synchronous notifications.
Technical details
The vulnerability is a process-dictionary state management error in AshGraphql.Subscription.Batcher.do_send/5. The function reads and unconditionally deletes a batch from Process.get(:batch_resolved) without namespacing by run ID. When do_send/5 runs inline in the publishing caller's process (on :backpressure_sync and :noproc fallbacks) and a resolver triggers a nested synchronous Ash notification, the inner call mistakenly reads and adopts the outer run's batch value, publishing it to the wrong subscription topic with different actor and tenant context. The fix saves, clears, and restores :batch_resolved around each run to isolate state. Affected versions: 1.4.0 to before 1.11.0. No exploitation in the wild reported.
Affected products
- ash-project ash_graphql 1.4.0 to before 1.11.0
Timeline
- 2026-08-30: disclosed
- 2026-08-30: advisory