{
  "id": "CVE-2026-94201",
  "url": "https://spydr.io/cve/CVE-2026-94201",
  "published": "2026-10-05T20:17:28.693Z",
  "modified": "2026-10-05T20:17:28.693Z",
  "score": 8.2,
  "severity": "high",
  "cvss_version": "4.0",
  "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
  "score_source": "CNA",
  "epss": null,
  "epss_percentile": null,
  "exploited": false,
  "kev": null,
  "ssvc_exploitation": null,
  "vendors": [
    "ash-project"
  ],
  "products": [
    "ash-project ash"
  ],
  "cwes": [
    "CWE-770"
  ],
  "description": "Ash stores :atom-typed attributes as strings and compares them as strings. When such an attribute is referenced in a filter, the comparison value is coerced through Ash.Type.Atom. Because the type defined no coerce/2 callback, coercion fell back to the default (cast_input/2), which calls String.to_atom/1 when the attribute is configured with the unsafe_to_atom?: true constraint. Filtering such an attribute with attacker-controlled strings therefore interned a new, permanent atom for every distinct value. Atoms are never garbage collected and the BEAM caps the atom table, so an actor who can supply filter values for a public, filterable :atom attribute declared with unsafe_to_atom?: true can exhaust the atom table and crash the node (denial of service). AshPaperTrail is a notable example: its version resources expose a public, filterable version_action_name atom attribute with unsafe_to_atom?: true by default. The fix adds a coerce/2 to Ash.Type.Atom that never interns atoms — a comparison value is left as a string, since the type is stored and compared as a string. Setting the attribute from action input (cast_input/2, which still honors unsafe_to_atom?) is unchanged. This issue affects ash: from 3.5.1 before 3.34.3.",
  "status": "Received",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": 8.2,
    "cvss_v31": null,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://cna.erlef.org/cves/CVE-2026-94201.html",
      "tags": []
    },
    {
      "url": "https://github.com/ash-project/ash/commit/2970ba3bd5d36d6ad04c731ac87385375d457147",
      "tags": []
    },
    {
      "url": "https://github.com/ash-project/ash/commit/5282f3f513053628cdd1bf2236ea22d975d934d4",
      "tags": []
    },
    {
      "url": "https://osv.dev/vulnerability/EEF-CVE-2026-94201",
      "tags": []
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94201",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
