{"schema_version":1,"title":"Ash-Project vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 60 vulnerabilities in Ash-Project: 1 in the last 7 days and 55 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-93477, was published on 25 September 2026. 7 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/ash-project","json_url":"https://junglewise.ai/threats/vendors/ash-project.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/ash-project","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":1,"all_time":60,"critical":0,"exploited":0,"last_7_days":1,"last_30_days":55,"last_90_days":55,"last_365_days":59},"latest":[{"cve":"CVE-2026-93477","epss":0.002,"slug":"cve-2026-93477-improperly-controlled-modification-of-dynamically-determined","title":"ash Improperly Controlled Modification of Object Attributes in bulk actions","severity":"info","exploited":false,"published_at":"2026-09-25T07:16:56.163+00:00","url":"https://junglewise.ai/threats/cve-2026-93477-improperly-controlled-modification-of-dynamically-determined"},{"cve":"CVE-2026-82710","epss":0.0066,"slug":"cve-2026-82710-ash-project-usage-rules-terminal-escape-sequence-injection","title":"ash-project usage_rules terminal escape sequence injection","severity":"info","exploited":false,"published_at":"2026-09-08T01:17:55.777+00:00","url":"https://junglewise.ai/threats/cve-2026-82710-ash-project-usage-rules-terminal-escape-sequence-injection"},{"cve":"CVE-2026-82758","cvss":7.5,"epss":0.0069,"slug":"cve-2026-82758-ash-project-ash-authentication-oauth2-server-authentication","title":"ash-project ash_authentication_oauth2_server authentication bypass in client registration","severity":"info","exploited":false,"published_at":"2026-09-07T23:16:53.123+00:00","url":"https://junglewise.ai/threats/cve-2026-82758-ash-project-ash-authentication-oauth2-server-authentication"},{"cve":"CVE-2026-82757","cvss":6.5,"epss":0.0067,"slug":"cve-2026-82757-ash-project-ash-authentication-oauth2-server-ssrf-in-metadata","title":"ash-project ash_authentication_oauth2_server SSRF in metadata fetch","severity":"info","exploited":false,"published_at":"2026-09-07T23:16:52.957+00:00","url":"https://junglewise.ai/threats/cve-2026-82757-ash-project-ash-authentication-oauth2-server-ssrf-in-metadata"},{"cve":"CVE-2026-82756","epss":0.0068,"slug":"cve-2026-82756-ash-project-ash-authentication-oauth2-server-parameter-injection","title":"ash-project ash_authentication_oauth2_server parameter injection in WWW-Authenticate header","severity":"info","exploited":false,"published_at":"2026-09-07T23:16:52.77+00:00","url":"https://junglewise.ai/threats/cve-2026-82756-ash-project-ash-authentication-oauth2-server-parameter-injection"},{"cve":"CVE-2026-82755","epss":0.0066,"slug":"cve-2026-82755-ash-project-ash-authentication-oauth2-server-cache-poisoning-in","title":"ash-project ash_authentication_oauth2_server cache poisoning in OAuth discovery metadata","severity":"info","exploited":false,"published_at":"2026-09-07T23:16:52.58+00:00","url":"https://junglewise.ai/threats/cve-2026-82755-ash-project-ash-authentication-oauth2-server-cache-poisoning-in"},{"cve":"CVE-2026-82754","epss":0.0069,"slug":"cve-2026-82754-ash-project-ash-authentication-oauth2-server-path-traversal-in","title":"ash-project ash_authentication_oauth2_server path traversal in OAuth endpoints","severity":"info","exploited":false,"published_at":"2026-09-07T23:16:52.403+00:00","url":"https://junglewise.ai/threats/cve-2026-82754-ash-project-ash-authentication-oauth2-server-path-traversal-in"},{"cve":"CVE-2026-82753","epss":0.0066,"slug":"cve-2026-82753-ash-project-ash-authentication-oauth2-server-unbound-resource","title":"ash-project ash_authentication_oauth2_server unbound resource allocation in /authorize","severity":"info","exploited":false,"published_at":"2026-09-07T23:16:52.227+00:00","url":"https://junglewise.ai/threats/cve-2026-82753-ash-project-ash-authentication-oauth2-server-unbound-resource"},{"cve":"CVE-2026-82586","epss":0.0052,"slug":"cve-2026-82586-ash-project-ash-lua-authorization-bypass-in-aggregation-read","title":"ash-project ash_lua authorization bypass in aggregation read","severity":"info","exploited":false,"published_at":"2026-09-07T23:16:52.093+00:00","url":"https://junglewise.ai/threats/cve-2026-82586-ash-project-ash-lua-authorization-bypass-in-aggregation-read"},{"cve":"CVE-2026-82584","epss":0.0053,"slug":"cve-2026-82584-ash-project-igniter-improper-escape-sequence-neutralization-in","title":"ash-project igniter improper escape sequence neutralization in package confirmation panel","severity":"info","exploited":false,"published_at":"2026-09-07T23:16:51.933+00:00","url":"https://junglewise.ai/threats/cve-2026-82584-ash-project-igniter-improper-escape-sequence-neutralization-in"},{"cve":"CVE-2026-81638","epss":0.0019,"slug":"cve-2026-81638-ash-project-ash-double-entry-ulid-encoding-bypass","title":"ash-project ash_double_entry ULID encoding bypass","severity":"info","exploited":false,"published_at":"2026-09-07T23:16:51.757+00:00","url":"https://junglewise.ai/threats/cve-2026-81638-ash-project-ash-double-entry-ulid-encoding-bypass"},{"cve":"CVE-2026-82733","cvss":7.5,"epss":0.0055,"slug":"cve-2026-82733-ash-project-ash-typescript-information-disclosure-in-error","title":"ash-project ash_typescript information disclosure in error responses","severity":"info","exploited":false,"published_at":"2026-09-01T03:16:53.373+00:00","url":"https://junglewise.ai/threats/cve-2026-82733-ash-project-ash-typescript-information-disclosure-in-error"},{"cve":"CVE-2026-82732","cvss":7.5,"epss":0.0068,"slug":"cve-2026-82732-ash-project-ash-typescript-input-validation-bypass-in","title":"ash-project ash_typescript input validation bypass in TypedController","severity":"info","exploited":false,"published_at":"2026-09-01T03:16:53.193+00:00","url":"https://junglewise.ai/threats/cve-2026-82732-ash-project-ash-typescript-input-validation-bypass-in"},{"cve":"CVE-2026-82731","cvss":6.1,"epss":0.005,"slug":"cve-2026-82731-ash-project-ash-typescript-open-redirect-in-typed-controller","title":"ash-project ash_typescript open redirect in typed controller routing","severity":"info","exploited":false,"published_at":"2026-09-01T03:16:52.993+00:00","url":"https://junglewise.ai/threats/cve-2026-82731-ash-project-ash-typescript-open-redirect-in-typed-controller"},{"cve":"CVE-2026-82730","cvss":5.3,"epss":0.005,"slug":"cve-2026-82730-ash-project-ash-typescript-unauthorized-attribute-disclosure-in","title":"ash-project ash_typescript unauthorized attribute disclosure in RPC","severity":"info","exploited":false,"published_at":"2026-09-01T03:16:52.787+00:00","url":"https://junglewise.ai/threats/cve-2026-82730-ash-project-ash-typescript-unauthorized-attribute-disclosure-in"},{"cve":"CVE-2026-77950","epss":0.0055,"slug":"cve-2026-77950-ash-project-ash-typescript-information-disclosure-in-error","title":"ash-project ash_typescript information disclosure in error handler","severity":"info","exploited":false,"published_at":"2026-09-01T03:16:51.66+00:00","url":"https://junglewise.ai/threats/cve-2026-77950-ash-project-ash-typescript-information-disclosure-in-error"},{"cve":"CVE-2026-77856","epss":0.0055,"slug":"cve-2026-77856-ash-project-ash-typescript-dos-via-atom-table-exhaustion","title":"ash-project ash_typescript DoS via atom table exhaustion","severity":"info","exploited":false,"published_at":"2026-09-01T03:16:51.5+00:00","url":"https://junglewise.ai/threats/cve-2026-77856-ash-project-ash-typescript-dos-via-atom-table-exhaustion"},{"cve":"CVE-2026-74837","cvss":7.5,"epss":0.0055,"slug":"cve-2026-74837-ash-project-ash-typescript-denial-of-service-via-resource","title":"ash-project ash_typescript denial of service via resource exhaustion","severity":"info","exploited":false,"published_at":"2026-09-01T03:16:51.187+00:00","url":"https://junglewise.ai/threats/cve-2026-74837-ash-project-ash-typescript-denial-of-service-via-resource"},{"cve":"CVE-2026-82727","cvss":0,"epss":0.0047,"slug":"cve-2026-82727-ash-project-ash-phoenix-sensitive-information-in-error-messages","title":"ash-project ash_phoenix sensitive information in error messages","severity":"info","exploited":false,"published_at":"2026-08-31T04:17:29.56+00:00","url":"https://junglewise.ai/threats/cve-2026-82727-ash-project-ash-phoenix-sensitive-information-in-error-messages"},{"cve":"CVE-2026-82726","epss":0.0052,"slug":"cve-2026-82726-ash-project-ash-phoenix-regular-expression-tenant-isolation","title":"ash-project ash_phoenix regular expression tenant isolation bypass","severity":"info","exploited":false,"published_at":"2026-08-31T04:17:29.357+00:00","url":"https://junglewise.ai/threats/cve-2026-82726-ash-project-ash-phoenix-regular-expression-tenant-isolation"},{"cve":"CVE-2026-82725","epss":0.0045,"slug":"cve-2026-82725-ash-project-ash-phoenix-authorization-bypass-through-user","title":"ash-project ash_phoenix authorization bypass through user-controlled key","severity":"info","exploited":false,"published_at":"2026-08-31T04:17:29.167+00:00","url":"https://junglewise.ai/threats/cve-2026-82725-ash-project-ash-phoenix-authorization-bypass-through-user"},{"cve":"CVE-2026-82724","epss":0.0043,"slug":"cve-2026-82724-ash-project-ash-phoenix-authorization-bypass-in-subdomainhook","title":"ash-project ash_phoenix authorization bypass in SubdomainHook","severity":"info","exploited":false,"published_at":"2026-08-31T04:17:28.98+00:00","url":"https://junglewise.ai/threats/cve-2026-82724-ash-project-ash-phoenix-authorization-bypass-in-subdomainhook"},{"cve":"CVE-2026-82722","epss":0.0047,"slug":"cve-2026-82722-ash-project-ash-admin-resource-exhaustion-in-liveview-handlers","title":"ash-project ash_admin resource exhaustion in LiveView handlers","severity":"info","exploited":false,"published_at":"2026-08-31T03:16:43.817+00:00","url":"https://junglewise.ai/threats/cve-2026-82722-ash-project-ash-admin-resource-exhaustion-in-liveview-handlers"},{"cve":"CVE-2026-82681","epss":0.0047,"slug":"cve-2026-82681-ash-project-ash-admin-improper-output-encoding-in-row-action","title":"ash-project ash_admin improper output encoding in row-action links","severity":"info","exploited":false,"published_at":"2026-08-31T03:16:43.643+00:00","url":"https://junglewise.ai/threats/cve-2026-82681-ash-project-ash-admin-improper-output-encoding-in-row-action"},{"cve":"CVE-2026-82673","cvss":8.2,"epss":0.0079,"slug":"cve-2026-82673-ash-project-ash-admin-path-traversal-in-file-upload","title":"ash-project ash_admin path traversal in file upload","severity":"info","exploited":false,"published_at":"2026-08-31T03:16:43.473+00:00","url":"https://junglewise.ai/threats/cve-2026-82673-ash-project-ash-admin-path-traversal-in-file-upload"}],"vendor":{"hub":true,"name":"Ash-Project","slug":"ash-project","url":"https://junglewise.ai/threats/vendors/ash-project"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":20},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":24},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":10},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1}],"most_severe":[{"cve":"CVE-2026-34593","cvss":7.5,"epss":0.0042,"slug":"cve-2026-34593-ash-framework-denial-of-service-via-atom-exhaustion-in-module","title":"Ash Framework Denial of Service via Atom Exhaustion in Module Type","severity":"high","exploited":false,"published_at":"2026-04-02T18:16:31.36+00:00","url":"https://junglewise.ai/threats/cve-2026-34593-ash-framework-denial-of-service-via-atom-exhaustion-in-module"},{"cve":"CVE-2026-55736","cvss":5.9,"epss":0.0037,"slug":"cve-2026-55736-ash-framework-private-argument-injection-in-ash-changeset","title":"Ash Framework private argument injection in Ash.Changeset","severity":"medium","exploited":false,"published_at":"2026-06-23T19:17:12.287+00:00","url":"https://junglewise.ai/threats/cve-2026-55736-ash-framework-private-argument-injection-in-ash-changeset"},{"cve":"CVE-2026-77956","cvss":9.8,"epss":0.0028,"slug":"cve-2026-77956-ash-project-ash-ai-code-injection-in-prompt-evaluation","title":"ash-project ash_ai code injection in prompt evaluation","severity":"info","exploited":false,"published_at":"2026-08-31T01:16:49.563+00:00","url":"https://junglewise.ai/threats/cve-2026-77956-ash-project-ash-ai-code-injection-in-prompt-evaluation"},{"cve":"CVE-2025-48044","cvss":8.6,"epss":0.0081,"slug":"cve-2025-48044-ash-framework-authorization-bypass-in-bypass-policy-logic","title":"Ash Framework authorization bypass in bypass policy logic","severity":"info","exploited":false,"published_at":"2025-10-17T14:15:46.403+00:00","url":"https://junglewise.ai/threats/cve-2025-48044-ash-framework-authorization-bypass-in-bypass-policy-logic"},{"cve":"CVE-2025-48043","cvss":8.6,"epss":0.0046,"slug":"cve-2025-48043-ash-framework-authentication-bypass-in-policy-authorizer","title":"Ash Framework Authentication Bypass in Policy Authorizer","severity":"info","exploited":false,"published_at":"2025-10-10T16:15:52.083+00:00","url":"https://junglewise.ai/threats/cve-2025-48043-ash-framework-authentication-bypass-in-policy-authorizer"},{"cve":"CVE-2026-82673","cvss":8.2,"epss":0.0079,"slug":"cve-2026-82673-ash-project-ash-admin-path-traversal-in-file-upload","title":"ash-project ash_admin path traversal in file upload","severity":"info","exploited":false,"published_at":"2026-08-31T03:16:43.473+00:00","url":"https://junglewise.ai/threats/cve-2026-82673-ash-project-ash-admin-path-traversal-in-file-upload"},{"cve":"CVE-2026-82758","cvss":7.5,"epss":0.0069,"slug":"cve-2026-82758-ash-project-ash-authentication-oauth2-server-authentication","title":"ash-project ash_authentication_oauth2_server authentication bypass in client registration","severity":"info","exploited":false,"published_at":"2026-09-07T23:16:53.123+00:00","url":"https://junglewise.ai/threats/cve-2026-82758-ash-project-ash-authentication-oauth2-server-authentication"},{"cve":"CVE-2026-82732","cvss":7.5,"epss":0.0068,"slug":"cve-2026-82732-ash-project-ash-typescript-input-validation-bypass-in","title":"ash-project ash_typescript input validation bypass in TypedController","severity":"info","exploited":false,"published_at":"2026-09-01T03:16:53.193+00:00","url":"https://junglewise.ai/threats/cve-2026-82732-ash-project-ash-typescript-input-validation-bypass-in"},{"cve":"CVE-2026-82733","cvss":7.5,"epss":0.0055,"slug":"cve-2026-82733-ash-project-ash-typescript-information-disclosure-in-error","title":"ash-project ash_typescript information disclosure in error responses","severity":"info","exploited":false,"published_at":"2026-09-01T03:16:53.373+00:00","url":"https://junglewise.ai/threats/cve-2026-82733-ash-project-ash-typescript-information-disclosure-in-error"},{"cve":"CVE-2026-74837","cvss":7.5,"epss":0.0055,"slug":"cve-2026-74837-ash-project-ash-typescript-denial-of-service-via-resource","title":"ash-project ash_typescript denial of service via resource exhaustion","severity":"info","exploited":false,"published_at":"2026-09-01T03:16:51.187+00:00","url":"https://junglewise.ai/threats/cve-2026-74837-ash-project-ash-typescript-denial-of-service-via-resource"}],"generated_at":"2026-09-26T11:07:00.153785+00:00","technologies":[{"name":"Ash-Project Ash Admin","slug":"ash-admin","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/ash-admin"},{"name":"Ash-Project Ash Typescript","slug":"ash-typescript","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/ash-typescript"},{"name":"Ash-Project Ash Ai","slug":"ash-ai","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/ash-ai"},{"name":"Ash-Project Ash Authentication Oauth2 Server","slug":"ash-authentication-oauth2-server","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/ash-authentication-oauth2-server"},{"name":"Ash-Project Ash Graphql","slug":"ash-graphql","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/ash-graphql"},{"name":"Ash-Project Ash Sql","slug":"ash-sql","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/ash-sql"},{"name":"Ash-Project Ash Phoenix","slug":"ash-phoenix","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/ash-phoenix"}]}