« Back to list

Ash-project

Ash-project ASH Typescript: vulnerabilities and CVEs

Ash-project ASH Typescript has 7 published vulnerabilities, 7 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs7
Last 12 months7
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-82733Medium (6.3)0.55%—Sep 1, 2026
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to read internal application data from an HTTP 500 response body. When a…
CVE-2026-82732Medium (6.3)0.68%—Sep 1, 2026
Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argument values outside a declared allowlist or bound on typed-controller routes.…
CVE-2026-82731Low (2.3)0.50%—Sep 1, 2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who controls a path-parameter value to redirect a generated client's request, and the credentials…
CVE-2026-82730High (8.2)0.50%—Sep 1, 2026
Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied. When a field policy denies an attribute, Ash substitutes…
CVE-2026-77950Medium (6.3)0.55%—Sep 1, 2026
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to receive unredacted internal error data by provoking an error shape the…
CVE-2026-77856High (8.2)0.55%—Sep 1, 2026
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied typed struct…
CVE-2026-74837High (8.7)0.55%—Sep 1, 2026
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied RPC field names.…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application3
  2. T1499.004 Application or System Exploitation2
  3. T1005 Data from Local System1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Ash-project