CVE-2026-74837
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied RPC field names.
AshTypescript.FieldFormatter.convert_to_field_atom/2 in lib/ash_typescript/field_formatter.ex converts a client-supplied field name to an atom with String.to_atom/1 when no matching atom already exists. It delegates first to parse_input_field/2, which resolves the name with String.to_existing_atom/1 and falls back to returning the plain string; convert_to_field_atom/2 then mints an atom from that string rather than treating the name as unknown.
Leer descripción completaMostrar menos
RPC field selection reaches it for every requested field name through AshTypescript.Rpc.FieldProcessing.FieldSelector, which resolves each name before checking that the field exists, with no allowlist, length bound, or rate limit. Atoms are never garbage collected, so each distinct name mints a permanent one and the VM aborts once the atom table limit is reached. A field name over 255 characters additionally raises an uncaught SystemLimitError.
This issue affects ash_typescript: from 0.1.0 before 0.18.0.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.55%
- Percentil entre todas las CVEs puntuadas: 44
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access95 % - Impacto principal
T1499.004Application or System Exploitationimpact90 %
Acceso en red sin autenticación (AV:N/PR:N/UI:N) permite enviar nombres de campo RPC arbitrarios. Agota la tabla de átomos BEAM causando DoS (Denial of Service) al abortar el nodo; CWE-770 (Allocation without limits).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-770
Referencias
- https://cna.erlef.org/cves/CVE-2026-74837.html
- https://github.com/ash-project/ash_typescript/commit/df95df4b9afdca5e5bbce32dbd566ccc49a7f14b
- https://github.com/ash-project/ash_typescript/security/advisories/GHSA-mhxc-mhqx-3v28
- https://osv.dev/vulnerability/EEF-CVE-2026-74837
- https://github.com/ash-project/ash_typescript/security/advisories/GHSA-mhxc-mhqx-3v28
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74837",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-74837",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-09-01T15:12:43.897916Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.7,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:ash-project:ash_typescript:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/ash-project/ash_typescript",
"vendor": "ash-project",
"modules": [
"'Elixir.AshTypescript.FieldFormatter'",
"'Elixir.AshTypescript.Rpc'",
"'Elixir.AshTypescript.Rpc.FieldProcessing.FieldSelector'"
],
"product": "ash_typescript",
"versions": [
{
"status": "affected",
"version": "0.1.0",
"lessThan": "0.18.0",
"versionType": "semver"
}
],
"packageURL": "pkg:hex/ash_typescript",
"packageName": "ash_typescript",
"programFiles": [
"lib/ash_typescript/field_formatter.ex",
"lib/ash_typescript/rpc.ex",
"lib/ash_typescript/rpc/field_processing/field_selector.ex"
],
"collectionURL": "https://repo.hex.pm",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "'Elixir.AshTypescript.FieldFormatter':convert_to_field_atom/2"
},
{
"name": "'Elixir.AshTypescript.FieldFormatter':parse_input_field/2"
},
{
"name": "'Elixir.AshTypescript.Rpc':run_action/3"
}
]
},
{
"cpes": [
"cpe:2.3:a:ash-project:ash_typescript:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/ash-project/ash_typescript",
"vendor": "ash-project",
"modules": [
"'Elixir.AshTypescript.FieldFormatter'",
"'Elixir.AshTypescript.Rpc'",
"'Elixir.AshTypescript.Rpc.FieldProcessing.FieldSelector'"
],
"product": "ash_typescript",
"versions": [
{
"status": "affected",
"version": "1a3d4c343430c8e4784acfcd33122a807fafa086",
"lessThan": "df95df4b9afdca5e5bbce32dbd566ccc49a7f14b",
"versionType": "git"
}
],
"packageURL": "pkg:github/ash-project/ash_typescript",
"packageName": "ash-project/ash_typescript",
"programFiles": [
"lib/ash_typescript/field_formatter.ex",
"lib/ash_typescript/rpc.ex",
"lib/ash_typescript/rpc/field_processing/field_selector.ex"
],
"collectionURL": "https://github.com",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "'Elixir.AshTypescript.FieldFormatter':convert_to_field_atom/2"
},
{
"name": "'Elixir.AshTypescript.FieldFormatter':parse_input_field/2"
},
{
"name": "'Elixir.AshTypescript.Rpc':run_action/3"
}
]
}
]
}
],
"published": "2026-09-01T03:16:51.187",
"references": [
{
"url": "https://cna.erlef.org/cves/CVE-2026-74837.html",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/ash-project/ash_typescript/commit/df95df4b9afdca5e5bbce32dbd566ccc49a7f14b",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/ash-project/ash_typescript/security/advisories/GHSA-mhxc-mhqx-3v28",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-74837",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/ash-project/ash_typescript/security/advisories/GHSA-mhxc-mhqx-3v28",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"description": [
{
"lang": "en",
"value": "CWE-770"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied RPC field names.\n\nAshTypescript.FieldFormatter.convert_to_field_atom/2 in lib/ash_typescript/field_formatter.ex converts a client-supplied field name to an atom with String.to_atom/1 when no matching atom already exists. It delegates first to parse_input_field/2, which resolves the name with String.to_existing_atom/1 and falls back to returning the plain string; convert_to_field_atom/2 then mints an atom from that string rather than treating the name as unknown.\n\nRPC field selection reaches it for every requested field name through AshTypescript.Rpc.FieldProcessing.FieldSelector, which resolves each name before checking that the field exists, with no allowlist, length bound, or rate limit. Atoms are never garbage collected, so each distinct name mints a permanent one and the VM aborts once the atom table limit is reached. A field name over 255 characters additionally raises an uncaught SystemLimitError.\n\nThis issue affects ash_typescript: from 0.1.0 before 0.18.0."
}
],
"lastModified": "2026-09-01T21:15:00.147",
"sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}