PT-2026-106202 · Unknown+1 · Ashjsonapi+3

·

CVE-2026-94201

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash versions 3.5.1 through 3.34.2
Description Ash stores :atom-typed attributes as strings and compares them as strings. When such an attribute is used in a filter, the comparison value is processed through Ash.Type.Atom. Due to the absence of a coerce/2 callback, the process defaults to cast input/2, which invokes String.to atom/1 when the attribute is configured with the unsafe to atom?: true constraint. An attacker providing distinct strings to a public, filterable :atom attribute with this constraint can cause the system to intern a new, permanent atom for every value. Since atoms are not garbage collected and the BEAM (the Erlang Virtual Machine) has a limited atom table, this can lead to atom table exhaustion and a denial of service crash. This is reachable when an application exposes such an attribute via interfaces like AshGraphql, AshJsonApi, or the filter input/2 function. AshPaperTrail is an example of a library that exposes the version action name attribute with this configuration by default.
Recommendations Update ash to version 3.34.3 or later. As a temporary mitigation, avoid using the unsafe to atom?: true constraint on public, filterable :atom attributes.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94201

Affected Products

Ash
Ash Graphql
Ashjsonapi
Ash Paper Trail