SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77856

HIGH · CVSS 8.2 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability in ash_typescript allows unauthenticated attackers to exploit the allocation of resources by supplying arbitrary field names, leading to the exhaustion of the BEAM atom table and potential node crashes. This can result in denial of service, as the system becomes unresponsive when the atom table limit is reached. Organizations using ash_typescript versions from 0.11.0 to before 0.18.0 should prioritize patching this vulnerability to safeguard against potential service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77856
Severity
HIGH
CVSS
8.2
EPSS
0.32%

Original NVD Description

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied typed struct field names. resolve_typed_struct_field/2 in lib/ash_typescript/rpc/field_processing/field_selector.ex looks a client-supplied field name up in the typed struct's reverse map and, when it finds no match, falls back to String.to_atom/1. Because this runs before any field-existence check, an unresolvable name mints a permanent atom rather than being rejected as unknown. Atoms are never garbage collected, so a request carrying many distinct names on a typed struct field grows the atom table until the VM aborts at its limit. This issue affects ash_typescript: from 0.11.0 before 0.18.0.