Intel

AIKIDO-2026-882562

ash is vulnerable to Uncontrolled Resource Consumption

Uncontrolled Resource ConsumptionCVE-2026-82742 Published 2 days ago

59

Medium Risk

This Affects:

ELIXIRash
1.30.0 - 3.32.1
Fixed in 3.32.2
Are you affected? Scan for Free

TL;DR

The runtime filter evaluator flattens records across relationship paths, producing an unbounded cartesian product when a filter spans multiple to-many relationships. The intermediate list is fully materialized with no bound on related data. A crafted filter can exhaust memory and CPU, causing denial of service. The fix streams relationship flattening so memory stays bounded.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you evaluate filters that span multiple to-many relationships in the runtime evaluator.

Background info

ash is vulnerable to Uncontrolled Resource Consumption in versions 1.30.0 - 3.32.1.

How to fix this

Upgrade the ash library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform