VYPR

ash_paper_trail

by Ash Project

CVEs (3)

  • CVE-2026-77970MedAug 30, 2026
    risk 0.31cvss epss

    Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists. sensitive_attributes :redact and :ignore…

  • CVE-2026-75847MedAug 30, 2026
    risk 0.31cvss epss

    Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of sensitive? attributes. AshPaperTrail stores the values of tracked sensitive? attributes in…

  • CVE-2026-77831LowAug 30, 2026
    risk 0.07cvss epss

    Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking,…