ash_double_entry
A customizable double entry bookkeeping system backed by Ash resources.
Activity
- Latest release
- 6d ago
- Total releases
- 29
- Cadence
- ~20 days
- Last 12 months
- 4
Reach
- Downloads
- 68.4k
- Stars
- 31
Details
- License
- MIT
- First release
- Aug 19, 2023
| Version | Released | |
|---|---|---|
1.0.19
patch
| ||
1.0.18
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.17
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.16
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.15
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.14
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.13
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.12
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.11
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.10
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.9
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.8
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.7
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.6
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.5
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.4
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.3
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.2
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.1
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
1.0.0-rc.0
pre
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.4
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.3
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.2
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.1
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.2
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.1
patch
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.0
initial
1 CVE
CVE-2026-81638
EEF-CVE-2026-81638
GHSA-qxp2-vgp9-268q
Sep 07, 2026
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Medium
Local
Low
None
None
SummaryImproper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.
This issue affects ash_double_entry: from 0.1.0 before 1.0.19. ConfigurationsReachable only when an application exposes Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
1.0.0
1.0.0-rc.0
1.0.1
1.0.10
+ 16 more Show less
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Fixed in
1.0.19
References Updated Sep 08, 2026 · Source: OSV.dev |