Ash-project
Ash-project ASH Typescript: vulnerabilities and CVEs
Ash-project ASH Typescript has 7 published vulnerabilities, 7 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months7
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82733 | Medium (6.3) | 0.55% | — | Sep 1, 2026 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to read internal application data from an HTTP 500 response body. When a… |
| CVE-2026-82732 | Medium (6.3) | 0.68% | — | Sep 1, 2026 | Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argument values outside a declared allowlist or bound on typed-controller routes.… |
| CVE-2026-82731 | Low (2.3) | 0.50% | — | Sep 1, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who controls a path-parameter value to redirect a generated client's request, and the credentials… |
| CVE-2026-82730 | High (8.2) | 0.50% | — | Sep 1, 2026 | Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied. When a field policy denies an attribute, Ash substitutes… |
| CVE-2026-77950 | Medium (6.3) | 0.55% | — | Sep 1, 2026 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to receive unredacted internal error data by provoking an error shape the… |
| CVE-2026-77856 | High (8.2) | 0.55% | — | Sep 1, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied typed struct… |
| CVE-2026-74837 | High (8.7) | 0.55% | — | Sep 1, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied RPC field names.… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.