VYPR

ash_cloak

by Ash Project

CVEs (2)

  • CVE-2026-81319MedAug 30, 2026
    risk 0.31cvss epss

    Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during decryption. AshCloak.Calculations.Decrypt…

  • CVE-2026-81322LowAug 30, 2026
    risk 0.07cvss epss

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts. …