ash_sql
A library containing some shared Ecto-based sql data layer functionality.
Activity
- Latest release
- 1w ago
- Total releases
- 160
- Cadence
- ~4 days
- Last 12 months
- 42
Reach
- Downloads
- 1.1M
- Stars
- 9
Details
- License
- MIT
- First release
- Apr 01, 2024
| Version | Released | |
|---|---|---|
0.7.3
patch
| ||
0.7.2
patch
| ||
0.7.1
patch
| ||
0.7.0
minor
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.6.9
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.6.8
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.6.7
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.6.6
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.6.5
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.6.4
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.6.3
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.6.2
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.6.1
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.6.0
minor
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.5
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.4
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.3
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.2
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.1
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.0
minor
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.5
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.4
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.3
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.2
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.1
patch
5 CVEs
CVE-2026-77454
EEF-CVE-2026-77454
GHSA-8v9m-8pxv-738c
Aug 30, 2026
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
High
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as
This issue affects ash_sql: from 0.4.1 before 0.7.1. ConfigurationsAn application must use Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
+ 10 more Show less
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.0
minor
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.16
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.15
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.14
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.13
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.12
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.11
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.10
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.9
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.8
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.7
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.6
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.5
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.4
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.3
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.2
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.1
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.0
minor
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.93
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.92
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.91
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.90
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.89
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.88
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.87
patch
4 CVEs
CVE-2026-81316
EEF-CVE-2026-81316
GHSA-v7pf-wjxc-7j5m
Aug 30, 2026
Same-named aggregates with differing filters are conflated in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must compute an aggregate whose name also reaches the query builder under a second, differently filtered context (for example the same aggregate used both as a filter dependency and loaded, where actor or tenant scoping stamps distinct filters onto each). Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-81318
EEF-CVE-2026-81318
GHSA-ww8j-58rc-f8h3
Aug 30, 2026
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use AshPostgres schema-based ( Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-78691
EEF-CVE-2026-78691
GHSA-5jgp-7mhc-6qqh
Aug 30, 2026
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Medium
Local
Low
None
None
SummaryImproper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to The escape helpers in This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1. ConfigurationsAn application must pass untrusted input as the search term of Affected versions
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
0.1.1-rc.20
0.1.2
+ 135 more Show less
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-80227
EEF-CVE-2026-80227
GHSA-76wx-w7ww-5xfq
Aug 30, 2026
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Medium
Local
Low
None
None
SummaryIncorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
This issue affects ash_sql: from 0.1.0 before 0.7.1. ConfigurationsAn application must use Affected versions
0.1.1-rc.0
0.1.1-rc.1
0.1.1-rc.10
0.1.1-rc.11
0.1.1-rc.12
0.1.1-rc.13
0.1.1-rc.14
0.1.1-rc.15
0.1.1-rc.16
0.1.1-rc.17
0.1.1-rc.18
0.1.1-rc.19
+ 145 more Show less
0.1.1-rc.2
0.1.1-rc.20
0.1.1-rc.3
0.1.1-rc.4
0.1.1-rc.5
0.1.1-rc.6
0.1.1-rc.7
0.1.1-rc.8
0.1.1-rc.9
0.1.2
0.1.3
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.32
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.41
0.2.42
0.2.43
0.2.44
0.2.45
0.2.46
0.2.47
0.2.48
0.2.49
0.2.5
0.2.50
0.2.51
0.2.52
0.2.53
0.2.54
0.2.55
0.2.56
0.2.57
0.2.58
0.2.59
0.2.6
0.2.60
0.2.61
0.2.62
0.2.63
0.2.64
0.2.65
0.2.66
0.2.67
0.2.68
0.2.69
0.2.7
0.2.70
0.2.71
0.2.72
0.2.73
0.2.74
0.2.75
0.2.76
0.2.77
0.2.78
0.2.79
0.2.8
0.2.80
0.2.81
0.2.82
0.2.83
0.2.84
0.2.85
0.2.86
0.2.87
0.2.88
0.2.89
0.2.9
0.2.90
0.2.91
0.2.92
0.2.93
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
Fixed in
0.7.1
References Updated Sep 08, 2026 · Source: OSV.dev |