ash is vulnerable to Improper Input Validation
21
Low Risk
Ash.Type.apply_constraints/3 for a nested {:array, {:array, type}} value applies only the inner item constraints and never enforces the outer array constraints. Declared limits such as maximum length are ignored, and nil entries in the outer list are not handled, which can raise unhandled exceptions. This affects nested array attributes and arguments populated from external input. The fix enforces the outer constraints and handles nil entries for nested arrays.
You are affected if you are using a version that falls within the vulnerable range and you expose nested array ({:array, {:array, type}}) attributes or arguments with constraints.
ash is vulnerable to Improper Input Validation in versions 2.16.1 - 3.32.1.
Upgrade the ash library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.