CVE-2026-80227
Received Received - Intake

Incorrect String Comparison in ash_sql Due to Whitespace Handling

Vulnerability report for CVE-2026-80227, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-30

Last updated on: 2026-08-30

Assigner: EEF

Description

Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse). string_trim/1 compiles to REGEXP_REPLACE patterns built from an Elixir string in which \s is the escape for a single space (codepoint 32), not a regex whitespace class. The generated SQL therefore removes only literal spaces and leaves tabs, newlines, carriage returns, and form feeds in place, whereas String.trim/1 in Elixir removes them all. Any Ash filter, validation, or identity that relies on string_trim/1 then behaves differently depending on whether Ash pushes the expression down to SQL or evaluates it in memory, so padded input can register a near-duplicate value or slip past a trimmed comparison. This issue affects ash_sql: from 0.1.0 before 0.7.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-30
Last Modified
2026-08-30
Generated
2026-08-30
AI Q&A
2026-08-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ash-project ash_sql From 0.1.0 (inc) to 0.7.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-697 The product compares two entities in a security-relevant context, but the comparison is incorrect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Incorrect Comparison issue in the ash_sql library where the string_trim function only removes literal spaces in SQL queries but Elixir's String.trim removes all whitespace. This causes discrepancies between database and memory checks, allowing padded strings to bypass uniqueness or equality validations.

Detection Guidance

To detect this vulnerability, inspect applications using ash_sql versions before 0.7.1 for string trimming operations. Check Elixir code for string_trim/1 usage in filters, validations, or identities. Compare SQL query results with in-memory validations for discrepancies in whitespace handling.

Impact Analysis

An attacker could register near-duplicate values by padding strings with tabs, newlines, or other whitespace. These values might pass database checks but fail in-memory validations, leading to data integrity issues like duplicate accounts or improper validations.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing near-duplicate or padded values to bypass uniqueness or equality checks in database operations. If an application relies on trimmed comparisons for user identities or sensitive data, attackers might register near-duplicate entries that evade validation, potentially violating data integrity requirements under these regulations.

Mitigation Strategies

Upgrade ash_sql to version 0.7.1 or later. Review and update any string trimming logic to ensure consistent behavior between SQL and Elixir memory. Test applications for near-duplicate values caused by whitespace padding.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80227. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart