CVE-2026-94201
Received Received - Intake

Atom Table Exhaustion in Ash Framework

Vulnerability report for CVE-2026-94201, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: EEF

Description

Ash stores :atom-typed attributes as strings and compares them as strings. When such an attribute is referenced in a filter, the comparison value is coerced through Ash.Type.Atom. Because the type defined no coerce/2 callback, coercion fell back to the default (cast_input/2), which calls String.to_atom/1 when the attribute is configured with the unsafe_to_atom?: true constraint. Filtering such an attribute with attacker-controlled strings therefore interned a new, permanent atom for every distinct value. Atoms are never garbage collected and the BEAM caps the atom table, so an actor who can supply filter values for a public, filterable :atom attribute declared with unsafe_to_atom?: true can exhaust the atom table and crash the node (denial of service). AshPaperTrail is a notable example: its version resources expose a public, filterable version_action_name atom attribute with unsafe_to_atom?: true by default. The fix adds a coerce/2 to Ash.Type.Atom that never interns atoms β€” a comparison value is left as a string, since the type is stored and compared as a string. Setting the attribute from action input (cast_input/2, which still honors unsafe_to_atom?) is unchanged. This issue affects ash: from 3.5.1 before 3.34.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ash-project ash 3.5.1
ash-project ash 2970ba3bd5d36d6ad04c731ac87385375d457147

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Ash framework allows an attacker to exhaust the BEAM atom table by filtering on an :atom attribute configured with unsafe_to_atom?: true. The system converts attacker-controlled strings into atoms using String.to_atom/1, which are never garbage collected. Repeated filtering with distinct values fills the atom table, crashing the node (denial of service).

Detection Guidance

To detect this vulnerability, check if your Ash framework version is between 3.5.1 and 3.34.3. Run: mix deps | grep ash. If the version falls in this range, the system is vulnerable. Additionally, inspect applications using AshPaperTrail or similar libraries for public, filterable :atom attributes with unsafe_to_atom?: true enabled.

Impact Analysis

If your application uses Ash and exposes a public, filterable :atom attribute with unsafe_to_atom?: true, an attacker could crash your system by sending many distinct filter values. This causes a denial of service, making the application unavailable.

Compliance Impact

This vulnerability could indirectly impact compliance with standards like GDPR and HIPAA by enabling denial-of-service attacks that disrupt system availability. A crash due to atom table exhaustion could lead to service unavailability, potentially violating availability requirements in GDPR Article 32 and HIPAA Security Rule Section 164.308(a)(7). However, the vulnerability itself does not directly expose or leak data, so confidentiality and integrity impacts are minimal.

Mitigation Strategies

Upgrade Ash to version 3.34.3 or later. For applications using AshPaperTrail, ensure version_action_name attributes are reviewed and updated if necessary. Disable unsafe_to_atom?: true for any exposed :atom attributes unless absolutely required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94201. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart