CVE-2026-69659
Last modified
CVE-2026-69659 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:after] or page[:before] cursor in decode_values/2 in lib/ash/page/keyset.ex, which base64-decodes the value and passes it to :erlang.binary_to_term/2 without bounding its size. The Erlang external term format supports zlib-compressed payloads, which the decoder inflates transparently, so a cursor of a few kilobytes can allocate tens of megabytes of heap in a single call. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:after] or page[:before] cursor in decode_values/2 in lib/ash/page/keyset.ex, which base64-decodes the value and passes it to :erlang.binary_to_term/2 without bounding its size. The Erlang external term format supports zlib-compressed payloads, which the decoder inflates transparently, so a cursor of a few kilobytes can allocate tens of megabytes of heap in a single call. Ash itself only ever encodes cursors uncompressed, so the decoder accepts a term shape its encoder never produces. Concurrent requests aggregate these allocations and can terminate the node. This issue affects ash: from 1.17.0 before 3.31.1.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ash-Hq | Ash Framework | >= 1.17.0, < 3.31.1 |
References
- https://cna.erlef.org/cves/CVE-2026-69659.htmlThird Party Advisory
- https://github.com/ash-project/ash/security/advisories/GHSA-j35q-v8h8-7mwqVendor Advisory, Patch
- https://osv.dev/vulnerability/EEF-CVE-2026-69659Third Party Advisory, Patch
- https://github.com/ash-project/ash/security/advisories/GHSA-j35q-v8h8-7mwqVendor Advisory, Patch
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-69659?
How severe is CVE-2026-69659?
How do I fix CVE-2026-69659?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-69649Heap-based buffer overflow in Windows Raw Image Extension al…8.8
- CVE-2026-6965The Tutor LMS – eLearning and online course solution plugin …5.3
- CVE-2026-69652Use after free in Windows Win32K allows an authorized attack…7
- CVE-2026-69654Use after free in Windows Accounts Control allows an authori…7
- CVE-2026-69657XING CPTrans-ME-X contains a Use of Default Password (CWE-13…9.3
- CVE-2026-69658MQTT credentials and control traffic are transmitted in clea…9.8
- CVE-2026-6966Improper verification of cryptographic signature uniqueness …6.5
- CVE-2026-69664Missing Release of Resource after Effective Lifetime vulnera…8.7
- CVE-2026-69665SKYSEA Client View and SKYMEC IT Manager contain an issue wi…8.5
- CVE-2026-69669Heap-based buffer overflow in Windows Kernel allows an unaut…8.8
- CVE-2026-6967Missing expiration, hash, and length enforcement in delegate…6.5
- CVE-2026-69671Heap-based buffer overflow in Microsoft Office Word allows a…8.8
Are you affected by CVE-2026-69659?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
