ash_cloak
An Ash extension to seamlessly encrypt and decrypt resource attributes.
Activity
- Latest release
- 2w ago
- Total releases
- 14
- Cadence
- ~42 days
- Last 12 months
- 5
Reach
- Downloads
- 195.3k
- Stars
- 30
Details
- License
- MIT
- First release
- Apr 25, 2024
| Version | Released | |
|---|---|---|
0.4.0
minor
| ||
0.3.1
patch
2 CVEs
CVE-2026-81322
EEF-CVE-2026-81322
GHSA-qp4v-vvrg-8ggx
Aug 30, 2026
Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
Medium
Local
Low
None
None
SummaryExposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsA resource must cloak an attribute that is not itself declared Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81319
EEF-CVE-2026-81319
GHSA-rc26-mrm2-6pf9
Aug 30, 2026
Unsafe deserialization of decrypted terms enables node DoS in AshCloak
High
Local
Low
None
None
SummaryDeserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during decryption.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsAn application must use ash_cloak with an unauthenticated vault cipher (for example the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.0
minor
2 CVEs
CVE-2026-81322
EEF-CVE-2026-81322
GHSA-qp4v-vvrg-8ggx
Aug 30, 2026
Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
Medium
Local
Low
None
None
SummaryExposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsA resource must cloak an attribute that is not itself declared Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81319
EEF-CVE-2026-81319
GHSA-rc26-mrm2-6pf9
Aug 30, 2026
Unsafe deserialization of decrypted terms enables node DoS in AshCloak
High
Local
Low
None
None
SummaryDeserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during decryption.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsAn application must use ash_cloak with an unauthenticated vault cipher (for example the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.1
patch
2 CVEs
CVE-2026-81322
EEF-CVE-2026-81322
GHSA-qp4v-vvrg-8ggx
Aug 30, 2026
Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
Medium
Local
Low
None
None
SummaryExposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsA resource must cloak an attribute that is not itself declared Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81319
EEF-CVE-2026-81319
GHSA-rc26-mrm2-6pf9
Aug 30, 2026
Unsafe deserialization of decrypted terms enables node DoS in AshCloak
High
Local
Low
None
None
SummaryDeserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during decryption.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsAn application must use ash_cloak with an unauthenticated vault cipher (for example the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.0
minor
2 CVEs
CVE-2026-81322
EEF-CVE-2026-81322
GHSA-qp4v-vvrg-8ggx
Aug 30, 2026
Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
Medium
Local
Low
None
None
SummaryExposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsA resource must cloak an attribute that is not itself declared Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81319
EEF-CVE-2026-81319
GHSA-rc26-mrm2-6pf9
Aug 30, 2026
Unsafe deserialization of decrypted terms enables node DoS in AshCloak
High
Local
Low
None
None
SummaryDeserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during decryption.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsAn application must use ash_cloak with an unauthenticated vault cipher (for example the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.7
patch
2 CVEs
CVE-2026-81322
EEF-CVE-2026-81322
GHSA-qp4v-vvrg-8ggx
Aug 30, 2026
Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
Medium
Local
Low
None
None
SummaryExposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsA resource must cloak an attribute that is not itself declared Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81319
EEF-CVE-2026-81319
GHSA-rc26-mrm2-6pf9
Aug 30, 2026
Unsafe deserialization of decrypted terms enables node DoS in AshCloak
High
Local
Low
None
None
SummaryDeserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during decryption.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsAn application must use ash_cloak with an unauthenticated vault cipher (for example the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.6
patch
2 CVEs
CVE-2026-81322
EEF-CVE-2026-81322
GHSA-qp4v-vvrg-8ggx
Aug 30, 2026
Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
Medium
Local
Low
None
None
SummaryExposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsA resource must cloak an attribute that is not itself declared Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81319
EEF-CVE-2026-81319
GHSA-rc26-mrm2-6pf9
Aug 30, 2026
Unsafe deserialization of decrypted terms enables node DoS in AshCloak
High
Local
Low
None
None
SummaryDeserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during decryption.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsAn application must use ash_cloak with an unauthenticated vault cipher (for example the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.5
patch
2 CVEs
CVE-2026-81322
EEF-CVE-2026-81322
GHSA-qp4v-vvrg-8ggx
Aug 30, 2026
Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
Medium
Local
Low
None
None
SummaryExposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsA resource must cloak an attribute that is not itself declared Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81319
EEF-CVE-2026-81319
GHSA-rc26-mrm2-6pf9
Aug 30, 2026
Unsafe deserialization of decrypted terms enables node DoS in AshCloak
High
Local
Low
None
None
SummaryDeserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during decryption.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsAn application must use ash_cloak with an unauthenticated vault cipher (for example the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.4
patch
2 CVEs
CVE-2026-81322
EEF-CVE-2026-81322
GHSA-qp4v-vvrg-8ggx
Aug 30, 2026
Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
Medium
Local
Low
None
None
SummaryExposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsA resource must cloak an attribute that is not itself declared Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81319
EEF-CVE-2026-81319
GHSA-rc26-mrm2-6pf9
Aug 30, 2026
Unsafe deserialization of decrypted terms enables node DoS in AshCloak
High
Local
Low
None
None
SummaryDeserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during decryption.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsAn application must use ash_cloak with an unauthenticated vault cipher (for example the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.3
patch
2 CVEs
CVE-2026-81322
EEF-CVE-2026-81322
GHSA-qp4v-vvrg-8ggx
Aug 30, 2026
Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
Medium
Local
Low
None
None
SummaryExposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsA resource must cloak an attribute that is not itself declared Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81319
EEF-CVE-2026-81319
GHSA-rc26-mrm2-6pf9
Aug 30, 2026
Unsafe deserialization of decrypted terms enables node DoS in AshCloak
High
Local
Low
None
None
SummaryDeserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during decryption.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsAn application must use ash_cloak with an unauthenticated vault cipher (for example the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.2
patch
2 CVEs
CVE-2026-81322
EEF-CVE-2026-81322
GHSA-qp4v-vvrg-8ggx
Aug 30, 2026
Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
Medium
Local
Low
None
None
SummaryExposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsA resource must cloak an attribute that is not itself declared Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81319
EEF-CVE-2026-81319
GHSA-rc26-mrm2-6pf9
Aug 30, 2026
Unsafe deserialization of decrypted terms enables node DoS in AshCloak
High
Local
Low
None
None
SummaryDeserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during decryption.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsAn application must use ash_cloak with an unauthenticated vault cipher (for example the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.1
patch
2 CVEs
CVE-2026-81322
EEF-CVE-2026-81322
GHSA-qp4v-vvrg-8ggx
Aug 30, 2026
Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
Medium
Local
Low
None
None
SummaryExposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsA resource must cloak an attribute that is not itself declared Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81319
EEF-CVE-2026-81319
GHSA-rc26-mrm2-6pf9
Aug 30, 2026
Unsafe deserialization of decrypted terms enables node DoS in AshCloak
High
Local
Low
None
None
SummaryDeserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during decryption.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsAn application must use ash_cloak with an unauthenticated vault cipher (for example the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.0
initial
2 CVEs
CVE-2026-81322
EEF-CVE-2026-81322
GHSA-qp4v-vvrg-8ggx
Aug 30, 2026
Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
Medium
Local
Low
None
None
SummaryExposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsA resource must cloak an attribute that is not itself declared Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81319
EEF-CVE-2026-81319
GHSA-rc26-mrm2-6pf9
Aug 30, 2026
Unsafe deserialization of decrypted terms enables node DoS in AshCloak
High
Local
Low
None
None
SummaryDeserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during decryption.
This issue affects ash_cloak: from 0.1.0 before 0.4.0. ConfigurationsAn application must use ash_cloak with an unauthenticated vault cipher (for example the Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
0.4.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.0-rc.0
pre
|