CVE-2026-82722
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Summary
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_admin lets any client that can reach the admin LiveView exhaust the BEAM atom table and crash the entire node.
Two LiveView event handlers interned atoms from unvalidated client input: AshAdmin.PageLive's set_actor built modules from the resource/domain payload with Module.concat/1, and AshAdmin.Components.Resource.Show's calculate converted every submitted form key with String.to_atom/1. Atoms are never garbage collected and the table is capped, so flooding either event with random names mints a new atom per request until the VM aborts, taking down every application on the node. The fix resolves the submitted resource/domain against the known shown resources and maps calculation keys to declared arguments, so no client-supplied string is interned.
This issue affects ash_admin: from 0.1.0 before 1.3.1.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ash-project | ash_admin | 0.1.0 < 1.3.1 | affected |
| ash-project | ash_admin | 98b03baa8422b94dd13e305bf08b8ee3f7232c7b < 731dffa09416d68f4ad3a0b6ee146b285ca0083b | affected |
Weaknesses
- CWE-770: CWE-770 Allocation of Resources Without Limits or Throttling
References
- https://github.com/ash-project/ash_admin/security/advisories/GHSA-wcr6-9rrw-5jhv
- https://cna.erlef.org/cves/CVE-2026-82722.html
- https://osv.dev/vulnerability/EEF-CVE-2026-82722
- https://github.com/ash-project/ash_admin/commit/731dffa09416d68f4ad3a0b6ee146b285ca0083b
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.