Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a record by storing a non-version-7 UUID in an Ash.Type.UUIDv7 attribute.
Ash.Type.UUIDv7.castinput/2 accepts any well-formed UUID string, including non-version-7 UUIDs, and stores it as a 16-byte binary. On read, caststored/2 (lib/ash/type/uuidv7.ex) routes the stored binary back through castinput/2, which since an input-validation tightening in v3.6.3 matches only version-7 (and optionally version-4) 16-byte binaries and otherwise expects a 36-character string. A stored non-v7 16-byte binary matches neither clause and returns :error, so every later read of that record fails. An attacker able to set such an attribute poisons the row permanently. The fix decodes any 16-byte stored binary directly in cast_stored/2.
This issue affects ash: from 3.6.3 before 3.32.2.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82738.json",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "3.6.3"
},
{
"fixed": "3.32.2"
},
{
"introduced": "751d8a4d11564efbe358c90c8347f3a00eb60782"
},
{
"fixed": "c453cdc0b8570e86ffef0d10e136247f52b3ea76"
}
]
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "3.6.3"
},
{
"fixed": "3.32.2"
}
]
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"introduced": "3.6.3"
},
{
"fixed": "3.32.2"
}
]
}
],
"cna_assigner": "EEF",
"cwe_ids": [
"CWE-20"
]
}