CVE-2026-70395Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to recover the secret value used to look it up. When manage_relationship is used with on_lookup: :relate on a belongs_to relationship, the client-supplied lookup value is passed to Ash.Query.filter/2 without being cast to the attribute type. A nested map submitted where a scalar is expected is therefore interpreted as a filter predicate rather than a literal, so a lookup for a specific record becomes a query for any record matching a condition. The same path omits Ash.Query.limit(1), leaving Ash.read_one/2 able to distinguish no match from one match from several, which turns comparison predicates into an oracle for the lookup value. Authorization is unaffected; the destination read policy still applies. This issue affects ash: from 1.52.0-rc.11 before 3.31.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-943

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-08-10)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-09: 1Mentions · 2026-08-10: 2Technical Details · 2026-08-09: 1Technical Details · 2026-08-10: 208-0908-10
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-091
Disclosure1
2026-08-102
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-70395 Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot na… https://www.cve.org/CVERecord?id=CVE-2026-70395 ----- Traducción: CVE-2026-70395 Fal… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-70395, providing its designation and a brief technical description, but offers no hints of PoC, exploit, active exploitation, or patch information.

    0000033
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-70395 Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot na… https://www.cve.org/CVERecord?id=CVE-2026-70395

    Post summary

    The tweet references CVE‑2026‑70395, noting it as an Improper Neutralization of Special Elements vulnerability that could allow an attacker to forge relationships; no PoC, exploit, patch, or active exploitation details are provided.

    000001.5K
    57.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-70395 Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to recover the secret va... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-70395

    Post summary

    The text announces CVE-2026-70395, describing an Improper Neutralization vulnerability that allows forging record relationships and retrieving secrets, but provides no PoC, exploit code, or patch information.

    00000153
    4.1K followersView on X

Explore more