The CVE-2026-70395 vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name and recover the secret value used to look it up. This is due to improper neutralization of special elements in data query logic when manage_relationship is used with on_lookup: :relate on a belongs_to relationship. The issue affects ash versions from 1.52.0-rc.11 before 3.31.1. Users [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T18:16:43.627Z and has not been modified since then. This Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. The vulnerability affects ash versions from 1.17.0 before 3.31.1. Developers and [truncated]
CVE-2026-55736 is an Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash. The issue allows a user to set the value of a private action argument intended to be controlled only by trusted server-side code. This occurs because Ash filters out private arguments incompletely when building a changeset from a parameter map. Specifically, private argumen [truncated]