VYPR

ash_oban

by Ash Project

CVEs (2)

  • CVE-2026-78228MedAug 30, 2026
    risk 0.31cvss epss

    Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to fail on the final attempt to exhaust worker CPU and memory, denying service. The generated worker's atomic handle_error/4 runs the trigger's on_error action…

  • CVE-2026-78038MedAug 30, 2026
    risk 0.31cvss epss

    Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to retarget an update or destroy trigger at another record, including across…