SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82738

MEDIUM · CVSS 5.9 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows attackers to exploit improper input validation in the Ash framework by storing non-version-7 UUIDs in the Ash.Type.UUIDv7 attribute, leading to persistent read failures for affected records. As a result, any attempts to retrieve these records will consistently return errors, effectively denying access to the data. Organizations using Ash versions from 3.6.3 to before 3.32.2 should prioritize remediation to prevent potential data loss or denial of service.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82738
Severity
MEDIUM
CVSS
5.9
EPSS
0.14%

Original NVD Description

Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a record by storing a non-version-7 UUID in an Ash.Type.UUIDv7 attribute. Ash.Type.UUIDv7.cast_input/2 accepts any well-formed UUID string, including non-version-7 UUIDs, and stores it as a 16-byte binary. On read, cast_stored/2 (lib/ash/type/uuid_v7.ex) routes the stored binary back through cast_input/2, which since an input-validation tightening in v3.6.3 matches only version-7 (and optionally version-4) 16-byte binaries and otherwise expects a 36-character string. A stored non-v7 16-byte binary matches neither clause and returns :error, so every later read of that record fails. An attacker able to set such an attribute poisons the row permanently. The fix decodes any 16-byte stored binary directly in cast_stored/2. This issue affects ash: from 3.6.3 before 3.32.2.