PT-2026-84085 · Ash · Ash

·

CVE-2026-82736

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v4.0

2.1

Low

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash versions 1.29.0-rc0 through 3.32.1
Description An issue exists where the software allows the storage of case-insensitive string values that violate length or match constraints. This occurs because the apply constraints/2 function in Ash.Type.CiString validates max length, min length, and match constraints against the submitted value before the string is case-folded for storage and comparison. Consequently, a value may pass validation in its original form but violate constraints once it is folded and stored.
Recommendations Update ash to version 3.32.2.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82736
GHSA-GG9W-7593-HXG9

Affected Products

Ash