ash_oban
The extension for integrating Ash resources with Oban.
Activity
- Latest release
- 2w ago
- Total releases
- 63
- Cadence
- ~8 days
- Last 12 months
- 22
Reach
- Downloads
- 456.4k
- Stars
- 41
Details
- License
- MIT
- First release
- May 01, 2023
| Version | Released | |
|---|---|---|
0.8.14
patch
| ||
0.8.13
patch
2 CVEs
CVE-2026-78228
EEF-CVE-2026-78228
GHSA-94p7-498r-mrhp
Aug 30, 2026
Unbounded handle_error recursion enables denial of service in AshOban triggers
High
Local
Low
None
None
SummaryUncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's The generated worker's atomic This issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14. ConfigurationsA trigger must declare an Affected versions
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
+ 2 more Show less
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.8.12
patch
2 CVEs
CVE-2026-78228
EEF-CVE-2026-78228
GHSA-94p7-498r-mrhp
Aug 30, 2026
Unbounded handle_error recursion enables denial of service in AshOban triggers
High
Local
Low
None
None
SummaryUncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's The generated worker's atomic This issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14. ConfigurationsA trigger must declare an Affected versions
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
+ 2 more Show less
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.8.11
patch
2 CVEs
CVE-2026-78228
EEF-CVE-2026-78228
GHSA-94p7-498r-mrhp
Aug 30, 2026
Unbounded handle_error recursion enables denial of service in AshOban triggers
High
Local
Low
None
None
SummaryUncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's The generated worker's atomic This issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14. ConfigurationsA trigger must declare an Affected versions
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
+ 2 more Show less
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.8.10
patch
2 CVEs
CVE-2026-78228
EEF-CVE-2026-78228
GHSA-94p7-498r-mrhp
Aug 30, 2026
Unbounded handle_error recursion enables denial of service in AshOban triggers
High
Local
Low
None
None
SummaryUncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's The generated worker's atomic This issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14. ConfigurationsA trigger must declare an Affected versions
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
+ 2 more Show less
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.8.9
patch
2 CVEs
CVE-2026-78228
EEF-CVE-2026-78228
GHSA-94p7-498r-mrhp
Aug 30, 2026
Unbounded handle_error recursion enables denial of service in AshOban triggers
High
Local
Low
None
None
SummaryUncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's The generated worker's atomic This issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14. ConfigurationsA trigger must declare an Affected versions
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
+ 2 more Show less
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.8.8
patch
2 CVEs
CVE-2026-78228
EEF-CVE-2026-78228
GHSA-94p7-498r-mrhp
Aug 30, 2026
Unbounded handle_error recursion enables denial of service in AshOban triggers
High
Local
Low
None
None
SummaryUncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's The generated worker's atomic This issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14. ConfigurationsA trigger must declare an Affected versions
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
+ 2 more Show less
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.8.7
patch
2 CVEs
CVE-2026-78228
EEF-CVE-2026-78228
GHSA-94p7-498r-mrhp
Aug 30, 2026
Unbounded handle_error recursion enables denial of service in AshOban triggers
High
Local
Low
None
None
SummaryUncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's The generated worker's atomic This issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14. ConfigurationsA trigger must declare an Affected versions
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
+ 2 more Show less
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.8.6
patch
2 CVEs
CVE-2026-78228
EEF-CVE-2026-78228
GHSA-94p7-498r-mrhp
Aug 30, 2026
Unbounded handle_error recursion enables denial of service in AshOban triggers
High
Local
Low
None
None
SummaryUncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's The generated worker's atomic This issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14. ConfigurationsA trigger must declare an Affected versions
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
+ 2 more Show less
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.8.5
patch
2 CVEs
CVE-2026-78228
EEF-CVE-2026-78228
GHSA-94p7-498r-mrhp
Aug 30, 2026
Unbounded handle_error recursion enables denial of service in AshOban triggers
High
Local
Low
None
None
SummaryUncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's The generated worker's atomic This issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14. ConfigurationsA trigger must declare an Affected versions
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
+ 2 more Show less
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.8.4
patch
2 CVEs
CVE-2026-78228
EEF-CVE-2026-78228
GHSA-94p7-498r-mrhp
Aug 30, 2026
Unbounded handle_error recursion enables denial of service in AshOban triggers
High
Local
Low
None
None
SummaryUncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's The generated worker's atomic This issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14. ConfigurationsA trigger must declare an Affected versions
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
+ 2 more Show less
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.8.3
patch
2 CVEs
CVE-2026-78228
EEF-CVE-2026-78228
GHSA-94p7-498r-mrhp
Aug 30, 2026
Unbounded handle_error recursion enables denial of service in AshOban triggers
High
Local
Low
None
None
SummaryUncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's The generated worker's atomic This issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14. ConfigurationsA trigger must declare an Affected versions
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
+ 2 more Show less
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.8.2
patch
2 CVEs
CVE-2026-78228
EEF-CVE-2026-78228
GHSA-94p7-498r-mrhp
Aug 30, 2026
Unbounded handle_error recursion enables denial of service in AshOban triggers
High
Local
Low
None
None
SummaryUncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's The generated worker's atomic This issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14. ConfigurationsA trigger must declare an Affected versions
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
+ 2 more Show less
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.8.1
minor
2 CVEs
CVE-2026-78228
EEF-CVE-2026-78228
GHSA-94p7-498r-mrhp
Aug 30, 2026
Unbounded handle_error recursion enables denial of service in AshOban triggers
High
Local
Low
None
None
SummaryUncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's The generated worker's atomic This issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14. ConfigurationsA trigger must declare an Affected versions
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
+ 2 more Show less
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.8.0-rc.1
pre
2 CVEs
CVE-2026-78228
EEF-CVE-2026-78228
GHSA-94p7-498r-mrhp
Aug 30, 2026
Unbounded handle_error recursion enables denial of service in AshOban triggers
High
Local
Low
None
None
SummaryUncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's The generated worker's atomic This issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14. ConfigurationsA trigger must declare an Affected versions
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
+ 2 more Show less
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.8.0-rc.0
pre
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.7.2
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.7.1
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.7.0
minor
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.6.0
minor
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.1
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.12
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.11
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.10
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.9
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.8
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.7
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.6
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.5
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.4
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.3
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.2
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.1
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.5
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.4
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.3
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.2
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.1
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.6
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.5
patch
1 CVE
CVE-2026-78038
EEF-CVE-2026-78038
GHSA-gj9p-x393-rf9h
Aug 30, 2026
Job argument injection via :args overrides primary_key and tenant in AshOban
High
Local
Low
None
None
SummaryImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the
This issue affects ash_oban: from 0.2.5 before 0.8.14. ConfigurationsAn application must pass untrusted input into the Affected versions
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
+ 30 more Show less
0.4.12
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0-rc.0
0.8.0-rc.1
0.8.1
0.8.10
0.8.11
0.8.12
0.8.13
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Fixed in
0.8.14
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.4
patch
| ||
0.2.3
patch
| ||
0.2.3-rc.1
pre
| ||
0.2.3-rc.0
pre
| ||
0.2.2
patch
| ||
0.2.1
patch
| ||
0.2.0
minor
|