CVE-2026-34593Patch(ash-hq / ash_framework)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ash-hq ash_framework systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type.Module.cast_input/2 unconditionally creates a new Erlang atom via Module.concat([value]) for any user-supplied binary string that starts with "Elixir.", before verifying whether the referenced module exists. Because Erlang atoms are never garbage-collected and the BEAM atom table has a hard default limit of approximately 1,048,576 entries, an attacker who can submit values to any resource attribute or argument of type :module can exhaust this table and crash the entire BEAM VM, taking down the application. This issue has been patched in version 3.22.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ash_framework

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ash_framework

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-01: 1Patch / Workaround · 2026-04-01: 1Technical Details · 2026-04-01: 104-01
Signal classification1 categories
Patch
1100.0%
Referenced assets3 URLs
Full discourse1 post
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    ⚡ CVE-2026-34593 (Ash.Type.Module.cast_input/2 Elixir): High atom exhaustion via unchecked Module.concat—BEAM VM crash DoS. Patch: Ash update https://www.tenable.com/cve/newest https://nvd.nist.gov/vuln/detail/CVE-2026-34593 https://hex.pm/packages/ash

    Post summary

    CVE‑2026‑34593 leads to a BEAM VM crash through atom exhaustion; a patch is available via an Ash update.

    100003
    492 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appash-hqash_framework---

Explore more