Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor.
Read actions with keyset pagination deserialize the client-supplied page[:after] or page[:before] cursor in decodevalues/2 in lib/ash/page/keyset.ex, which base64-decodes the value and passes it to :erlang.binaryto_term/2 without bounding its size. The Erlang external term format supports zlib-compressed payloads, which the decoder inflates transparently, so a cursor of a few kilobytes can allocate tens of megabytes of heap in a single call. Ash itself only ever encodes cursors uncompressed, so the decoder accepts a term shape its encoder never produces. Concurrent requests aggregate these allocations and can terminate the node.
This issue affects ash: from 1.17.0 before 3.31.1.
{
"cwe_ids": [
"CWE-502"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69659.json",
"cna_assigner": "EEF",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "1.17.0"
},
{
"fixed": "3.31.1"
},
{
"introduced": "f8fadc67e67c955bb68b3a8d642be13e2b7e8ca9"
},
{
"fixed": "1816b103af975221210478d61db20adcea700319"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"introduced": "1.17.0"
},
{
"fixed": "3.31.1"
}
],
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"introduced": "1.17.0"
},
{
"fixed": "3.31.1"
}
],
"source": "DESCRIPTION"
}
]
}