PT-2026-106202 · Unknown+1 · Ashjsonapi+3
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash versions 3.5.1 through 3.34.2
Description
Ash stores
:atom-typed attributes as strings and compares them as strings. When such an attribute is used in a filter, the comparison value is processed through Ash.Type.Atom. Due to the absence of a coerce/2 callback, the process defaults to cast input/2, which invokes String.to atom/1 when the attribute is configured with the unsafe to atom?: true constraint. An attacker providing distinct strings to a public, filterable :atom attribute with this constraint can cause the system to intern a new, permanent atom for every value. Since atoms are not garbage collected and the BEAM (the Erlang Virtual Machine) has a limited atom table, this can lead to atom table exhaustion and a denial of service crash. This is reachable when an application exposes such an attribute via interfaces like AshGraphql, AshJsonApi, or the filter input/2 function. AshPaperTrail is an example of a library that exposes the version action name attribute with this configuration by default.Recommendations
Update ash to version 3.34.3 or later.
As a temporary mitigation, avoid using the
unsafe to atom?: true constraint on public, filterable :atom attributes.Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash
Ash Graphql
Ashjsonapi
Ash Paper Trail