Vendor
Ash-Project vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 60 vulnerabilities in Ash-Project: 1 in the last 7 days and 55 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-93477, was published on 25 September 2026. 7 technologies have a page of their own.
- Last 7 days
- 1
- Last 90 days
- 55
- Critical, all time
- 0
- Exploited in the wild
- 0
Ash-Project technologies
Latest Ash-Project vulnerabilities
- CVE-2026-93477: ash Improperly Controlled Modification of Object Attributes in bulk actionsinfoEPSS 0.2%
- CVE-2026-82710: ash-project usage_rules terminal escape sequence injectioninfoEPSS 0.7%
- CVE-2026-82758: ash-project ash_authentication_oauth2_server authentication bypass in client registrationinfoCVSS 7.5EPSS 0.7%
- CVE-2026-82757: ash-project ash_authentication_oauth2_server SSRF in metadata fetchinfoCVSS 6.5EPSS 0.7%
- CVE-2026-82756: ash-project ash_authentication_oauth2_server parameter injection in WWW-Authenticate headerinfoEPSS 0.7%
- CVE-2026-82755: ash-project ash_authentication_oauth2_server cache poisoning in OAuth discovery metadatainfoEPSS 0.7%
- CVE-2026-82754: ash-project ash_authentication_oauth2_server path traversal in OAuth endpointsinfoEPSS 0.7%
- CVE-2026-82753: ash-project ash_authentication_oauth2_server unbound resource allocation in /authorizeinfoEPSS 0.7%
- CVE-2026-82586: ash-project ash_lua authorization bypass in aggregation readinfoEPSS 0.5%
- CVE-2026-82584: ash-project igniter improper escape sequence neutralization in package confirmation panelinfoEPSS 0.5%
- CVE-2026-81638: ash-project ash_double_entry ULID encoding bypassinfoEPSS 0.2%
- CVE-2026-82733: ash-project ash_typescript information disclosure in error responsesinfoCVSS 7.5EPSS 0.5%
- CVE-2026-82732: ash-project ash_typescript input validation bypass in TypedControllerinfoCVSS 7.5EPSS 0.7%
- CVE-2026-82731: ash-project ash_typescript open redirect in typed controller routinginfoCVSS 6.1EPSS 0.5%
- CVE-2026-82730: ash-project ash_typescript unauthorized attribute disclosure in RPCinfoCVSS 5.3EPSS 0.5%
- CVE-2026-77950: ash-project ash_typescript information disclosure in error handlerinfoEPSS 0.5%
- CVE-2026-77856: ash-project ash_typescript DoS via atom table exhaustioninfoEPSS 0.5%
- CVE-2026-74837: ash-project ash_typescript denial of service via resource exhaustioninfoCVSS 7.5EPSS 0.5%
- CVE-2026-82727: ash-project ash_phoenix sensitive information in error messagesinfoCVSS 0EPSS 0.5%
- CVE-2026-82726: ash-project ash_phoenix regular expression tenant isolation bypassinfoEPSS 0.5%
- CVE-2026-82725: ash-project ash_phoenix authorization bypass through user-controlled keyinfoEPSS 0.4%
- CVE-2026-82724: ash-project ash_phoenix authorization bypass in SubdomainHookinfoEPSS 0.4%
- CVE-2026-82722: ash-project ash_admin resource exhaustion in LiveView handlersinfoEPSS 0.5%
- CVE-2026-82681: ash-project ash_admin improper output encoding in row-action linksinfoEPSS 0.5%
- CVE-2026-82673: ash-project ash_admin path traversal in file uploadinfoCVSS 8.2EPSS 0.8%
Most severe Ash-Project vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-34593: Ash Framework Denial of Service via Atom Exhaustion in Module TypehighCVSS 7.5EPSS 0.4%
- CVE-2026-55736: Ash Framework private argument injection in Ash.ChangesetmediumCVSS 5.9EPSS 0.4%
- CVE-2026-77956: ash-project ash_ai code injection in prompt evaluationinfoCVSS 9.8EPSS 0.3%
- CVE-2025-48044: Ash Framework authorization bypass in bypass policy logicinfoCVSS 8.6EPSS 0.8%
- CVE-2025-48043: Ash Framework Authentication Bypass in Policy AuthorizerinfoCVSS 8.6EPSS 0.5%
- CVE-2026-82673: ash-project ash_admin path traversal in file uploadinfoCVSS 8.2EPSS 0.8%
- CVE-2026-82758: ash-project ash_authentication_oauth2_server authentication bypass in client registrationinfoCVSS 7.5EPSS 0.7%
- CVE-2026-82732: ash-project ash_typescript input validation bypass in TypedControllerinfoCVSS 7.5EPSS 0.7%
- CVE-2026-82733: ash-project ash_typescript information disclosure in error responsesinfoCVSS 7.5EPSS 0.5%
- CVE-2026-74837: ash-project ash_typescript denial of service via resource exhaustioninfoCVSS 7.5EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 20 | 0 | |
| 31 Aug 2026 | 24 | 0 | |
| 7 Sep 2026 | 10 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 1 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/ash-project.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Ash-Project vulnerabilities", https://junglewise.ai/threats/vendors/ash-project, 26 September 2026.