← العودة للجدول
CVE-2026-82736
CVE-2026-82736 — Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-proj
📅 2026-09-01
🟡 Medium 🔥 No NVD Vulnerability Vulnerability

📋 الوصف الكامل

Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-insensitive string value that violates its length or match constraints. Ash.Type.CiString.apply_constraints/2 (lib/ash/type/ci_string.ex) validated the max_length, min_length, and match constraints against the value as submitted, while the type case-folds the string (per its casin

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-82736

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-82736 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←