PT-2026-84085 · Ash · Ash
CVSS v4.0
2.1
Low
| Vector | AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash versions 1.29.0-rc0 through 3.32.1
Description
An issue exists where the software allows the storage of case-insensitive string values that violate length or match constraints. This occurs because the
apply constraints/2 function in Ash.Type.CiString validates max length, min length, and match constraints against the submitted value before the string is case-folded for storage and comparison. Consequently, a value may pass validation in its original form but violate constraints once it is folded and stored.Recommendations
Update ash to version 3.32.2.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash