ash_paper_trail
The extension for keeping an audit log of changes to your Ash resources.
Activity
- Latest release
- 2w ago
- Total releases
- 21
- Cadence
- ~34 days
- Last 12 months
- 3
Reach
- Downloads
- 273.9k
- Stars
- 53
Details
- License
- MIT
- First release
- Jan 31, 2024
| Version | Released | |
|---|---|---|
0.7.0
minor
| ||
0.6.0
minor
3 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77970
EEF-CVE-2026-77970
GHSA-v645-6jm6-cgpj
Aug 30, 2026
Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists.
This issue affects ash_paper_trail: from 0.3.0 before 0.7.0. ConfigurationsThe resource must version an attribute or accept an action input whose type is an embedded resource, union, or list containing a Affected versions
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.7
patch
3 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77970
EEF-CVE-2026-77970
GHSA-v645-6jm6-cgpj
Aug 30, 2026
Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists.
This issue affects ash_paper_trail: from 0.3.0 before 0.7.0. ConfigurationsThe resource must version an attribute or accept an action input whose type is an embedded resource, union, or list containing a Affected versions
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.6
patch
3 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77970
EEF-CVE-2026-77970
GHSA-v645-6jm6-cgpj
Aug 30, 2026
Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists.
This issue affects ash_paper_trail: from 0.3.0 before 0.7.0. ConfigurationsThe resource must version an attribute or accept an action input whose type is an embedded resource, union, or list containing a Affected versions
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.5
patch
3 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77970
EEF-CVE-2026-77970
GHSA-v645-6jm6-cgpj
Aug 30, 2026
Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists.
This issue affects ash_paper_trail: from 0.3.0 before 0.7.0. ConfigurationsThe resource must version an attribute or accept an action input whose type is an embedded resource, union, or list containing a Affected versions
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.4
patch
3 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77970
EEF-CVE-2026-77970
GHSA-v645-6jm6-cgpj
Aug 30, 2026
Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists.
This issue affects ash_paper_trail: from 0.3.0 before 0.7.0. ConfigurationsThe resource must version an attribute or accept an action input whose type is an embedded resource, union, or list containing a Affected versions
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.3
patch
3 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77970
EEF-CVE-2026-77970
GHSA-v645-6jm6-cgpj
Aug 30, 2026
Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists.
This issue affects ash_paper_trail: from 0.3.0 before 0.7.0. ConfigurationsThe resource must version an attribute or accept an action input whose type is an embedded resource, union, or list containing a Affected versions
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.2
patch
3 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77970
EEF-CVE-2026-77970
GHSA-v645-6jm6-cgpj
Aug 30, 2026
Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists.
This issue affects ash_paper_trail: from 0.3.0 before 0.7.0. ConfigurationsThe resource must version an attribute or accept an action input whose type is an embedded resource, union, or list containing a Affected versions
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.1
patch
3 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77970
EEF-CVE-2026-77970
GHSA-v645-6jm6-cgpj
Aug 30, 2026
Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists.
This issue affects ash_paper_trail: from 0.3.0 before 0.7.0. ConfigurationsThe resource must version an attribute or accept an action input whose type is an embedded resource, union, or list containing a Affected versions
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.0
minor
3 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77970
EEF-CVE-2026-77970
GHSA-v645-6jm6-cgpj
Aug 30, 2026
Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists.
This issue affects ash_paper_trail: from 0.3.0 before 0.7.0. ConfigurationsThe resource must version an attribute or accept an action input whose type is an embedded resource, union, or list containing a Affected versions
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.0
minor
3 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77970
EEF-CVE-2026-77970
GHSA-v645-6jm6-cgpj
Aug 30, 2026
Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists.
This issue affects ash_paper_trail: from 0.3.0 before 0.7.0. ConfigurationsThe resource must version an attribute or accept an action input whose type is an embedded resource, union, or list containing a Affected versions
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.1
patch
3 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77970
EEF-CVE-2026-77970
GHSA-v645-6jm6-cgpj
Aug 30, 2026
Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists.
This issue affects ash_paper_trail: from 0.3.0 before 0.7.0. ConfigurationsThe resource must version an attribute or accept an action input whose type is an embedded resource, union, or list containing a Affected versions
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.0
minor
3 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-77970
EEF-CVE-2026-77970
GHSA-v645-6jm6-cgpj
Aug 30, 2026
Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists.
This issue affects ash_paper_trail: from 0.3.0 before 0.7.0. ConfigurationsThe resource must version an attribute or accept an action input whose type is an embedded resource, union, or list containing a Affected versions
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.1
patch
2 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.0
minor
2 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.4
patch
2 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.3
patch
2 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.2
patch
2 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.2-rc.0
pre
2 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.1
patch
2 CVEs
CVE-2026-77831
EEF-CVE-2026-77831
GHSA-7c66-59m8-723c
Aug 30, 2026
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Medium
Local
Low
None
None
SummaryInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe resource must use full-diff change tracking ( Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-75847
EEF-CVE-2026-75847
GHSA-wqjr-xmxp-j554
Aug 30, 2026
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
High
Local
Low
None
None
SummaryCleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of AshPaperTrail stores the values of tracked This issue affects ash_paper_trail: from 0.1.1 before 0.7.0. ConfigurationsThe tracked resource must declare one or more Affected versions
0.1.1
0.1.2
0.1.2-rc.0
0.1.3
0.1.4
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
+ 7 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
Fixed in
0.7.0
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.0
initial
|