Refine your search

2 vulnerabilities found for ash_oban by ash-project

CVE-2026-78228 (GCVE-0-2026-78228)
Vulnerability from cvelistv5
Published
2026-08-30 11:51
Modified
2026-08-30 11:51
CWE
Summary
Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to fail on the final attempt to exhaust worker CPU and memory, denying service. The generated worker's atomic handle_error/4 runs the trigger's on_error action on a job's final attempt inside a rescue that, when the action itself raises, calls handle_error/4 again with the same job. The job's attempt still equals max_attempts, so it re-enters the same clause and re-runs the failing action, with no exit. Any deterministic on_error failure (a data-layer outage, a misconfigured action, or a record the action rejects) loops forever; because the recursive call is not in tail position, each iteration retains a formatted stacktrace and the process heap grows without bound while the failing statement is re-issued against the data layer until the runtime kills the worker. This issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14.
Impacted products
Vendor Product Version
ash-project ash_oban Version: 0.8.0-rc.1   
    cpe:2.3:a:ash-project:ash_oban:*:*:*:*:*:*:*:*
Create a notification for this product.
   ash-project ash_oban Version: 5d117ed2006df7277561c69dbfd39281da6ace9f
    cpe:2.3:a:ash-project:ash_oban:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "collectionURL": "https://repo.hex.pm",
          "cpes": [
            "cpe:2.3:a:ash-project:ash_oban:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "modules": [
            "\u0027Elixir.AshOban.Transformers.DefineSchedulers\u0027"
          ],
          "packageName": "ash_oban",
          "packageURL": "pkg:hex/ash_oban",
          "product": "ash_oban",
          "programFiles": [
            "lib/transformers/define_schedulers.ex"
          ],
          "programRoutines": [
            {
              "name": "\u0027Elixir.AshOban.Transformers.DefineSchedulers\u0027:handle_error/4"
            }
          ],
          "repo": "https://github.com/ash-project/ash_oban",
          "vendor": "ash-project",
          "versions": [
            {
              "lessThan": "0.8.14",
              "status": "affected",
              "version": "0.8.0-rc.1",
              "versionType": "semver"
            }
          ]
        },
        {
          "collectionURL": "https://github.com",
          "cpes": [
            "cpe:2.3:a:ash-project:ash_oban:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "modules": [
            "\u0027Elixir.AshOban.Transformers.DefineSchedulers\u0027"
          ],
          "packageName": "ash-project/ash_oban",
          "packageURL": "pkg:github/ash-project/ash_oban",
          "product": "ash_oban",
          "programFiles": [
            "lib/transformers/define_schedulers.ex"
          ],
          "programRoutines": [
            {
              "name": "\u0027Elixir.AshOban.Transformers.DefineSchedulers\u0027:handle_error/4"
            }
          ],
          "repo": "https://github.com/ash-project/ash_oban",
          "vendor": "ash-project",
          "versions": [
            {
              "lessThan": "851cd0e76ed882bf736fc48d10f96d037e26b5f0",
              "status": "affected",
              "version": "5d117ed2006df7277561c69dbfd39281da6ace9f",
              "versionType": "git"
            }
          ]
        }
      ],
      "configurations": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eA trigger must declare an \u003ccode\u003eon_error\u003c/code\u003e action and run through the atomic worker branch. An attacker needs only to drive that \u003ccode\u003eon_error\u003c/code\u003e action into a deterministic failure (for example by pushing the record into a state the action rejects) and let the job reach its final attempt.\u003c/p\u003e"
            },
            {
              "base64": false,
              "type": "text/markdown",
              "value": "A trigger must declare an `on_error` action and run through the atomic worker branch. An attacker needs only to drive that `on_error` action into a deterministic failure (for example by pushing the record into a state the action rejects) and let the job reach its final attempt."
            }
          ],
          "value": "A trigger must declare an on_error action and run through the atomic worker branch. An attacker needs only to drive that on_error action into a deterministic failure (for example by pushing the record into a state the action rejects) and let the job reach its final attempt."
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:ash-project:ash_oban:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "0.8.14",
                  "versionStartIncluding": "0.8.0-rc.1",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ],
          "operator": "AND"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Peter Ullrich"
        },
        {
          "lang": "en",
          "type": "reporter",
          "value": "Peter Ullrich"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "Zach Daniel / Ash Project"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "Jonatan M\u00e4nnchen / EEF"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eUncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger\u0027s \u003ccode\u003eon_error\u003c/code\u003e action to fail on the final attempt to exhaust worker CPU and memory, denying service.\u003c/p\u003e\n\u003cp\u003eThe generated worker\u0027s atomic \u003ccode\u003ehandle_error/4\u003c/code\u003e runs the trigger\u0027s \u003ccode\u003eon_error\u003c/code\u003e action on a job\u0027s final attempt inside a \u003ccode\u003erescue\u003c/code\u003e that, when the action itself raises, calls \u003ccode\u003ehandle_error/4\u003c/code\u003e again with the same job. The job\u0027s \u003ccode\u003eattempt\u003c/code\u003e still equals \u003ccode\u003emax_attempts\u003c/code\u003e, so it re-enters the same clause and re-runs the failing action, with no exit. Any deterministic \u003ccode\u003eon_error\u003c/code\u003e failure (a data-layer outage, a misconfigured action, or a record the action rejects) loops forever; because the recursive call is not in tail position, each iteration retains a formatted stacktrace and the process heap grows without bound while the failing statement is re-issued against the data layer until the runtime kills the worker.\u003c/p\u003e\n\u003cp\u003eThis issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14.\u003c/p\u003e"
            },
            {
              "base64": false,
              "type": "text/markdown",
              "value": "Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger\u0027s `on_error` action to fail on the final attempt to exhaust worker CPU and memory, denying service.\n\nThe generated worker\u0027s atomic `handle_error/4` runs the trigger\u0027s `on_error` action on a job\u0027s final attempt inside a `rescue` that, when the action itself raises, calls `handle_error/4` again with the same job. The job\u0027s `attempt` still equals `max_attempts`, so it re-enters the same clause and re-runs the failing action, with no exit. Any deterministic `on_error` failure (a data-layer outage, a misconfigured action, or a record the action rejects) loops forever; because the recursive call is not in tail position, each iteration retains a formatted stacktrace and the process heap grows without bound while the failing statement is re-issued against the data layer until the runtime kills the worker.\n\nThis issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14."
            }
          ],
          "value": "Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger\u0027s on_error action to fail on the final attempt to exhaust worker CPU and memory, denying service.\n\nThe generated worker\u0027s atomic handle_error/4 runs the trigger\u0027s on_error action on a job\u0027s final attempt inside a rescue that, when the action itself raises, calls handle_error/4 again with the same job. The job\u0027s attempt still equals max_attempts, so it re-enters the same clause and re-runs the failing action, with no exit. Any deterministic on_error failure (a data-layer outage, a misconfigured action, or a record the action rejects) loops forever; because the recursive call is not in tail position, each iteration retains a formatted stacktrace and the process heap grows without bound while the failing statement is re-issued against the data layer until the runtime kills the worker.\n\nThis issue affects ash_oban: from 0.8.0-rc.1 before 0.8.14."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-130",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-130 Excessive Allocation"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "LOCAL",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-674",
              "description": "CWE-674 Uncontrolled Recursion",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-30T11:51:49.621Z",
        "orgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "shortName": "EEF"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "related"
          ],
          "url": "https://github.com/ash-project/ash_oban/security/advisories/GHSA-94p7-498r-mrhp"
        },
        {
          "tags": [
            "related"
          ],
          "url": "https://cna.erlef.org/cves/CVE-2026-78228.html"
        },
        {
          "tags": [
            "related"
          ],
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-78228"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://github.com/ash-project/ash_oban/commit/851cd0e76ed882bf736fc48d10f96d037e26b5f0"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "Unbounded handle_error recursion enables denial of service in AshOban triggers"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "assignerShortName": "EEF",
    "cveId": "CVE-2026-78228",
    "datePublished": "2026-08-30T11:51:49.621Z",
    "dateReserved": "2026-08-30T00:00:01.991Z",
    "dateUpdated": "2026-08-30T11:51:49.621Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-78038 (GCVE-0-2026-78038)
Vulnerability from cvelistv5
Published
2026-08-30 11:50
Modified
2026-08-30 11:50
CWE
  • CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
Summary
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to retarget an update or destroy trigger at another record, including across tenants. build_trigger/3 builds the trusted job arguments with atom keys (:primary_key, :tenant, :action_arguments) and merges the caller's :args underneath so the trusted values win on collision. Because Oban job arguments round-trip through JSON, the caller's keys arrive as strings, so Map.merge sees no collision and both keys survive. When the job is persisted the JSON object is de-duplicated keeping the last (string) key, and the worker reads the caller's value. The documentation describes :args as unable to affect the action, so an application that forwards user input into it for uniqueness scoping is exposed to authorization bypass and tenant isolation breaks. This issue affects ash_oban: from 0.2.5 before 0.8.14.
Impacted products
Vendor Product Version
ash-project ash_oban Version: 0.2.5   
    cpe:2.3:a:ash-project:ash_oban:*:*:*:*:*:*:*:*
Create a notification for this product.
   ash-project ash_oban Version: ce079229ecdf0d323da2b554f30fc569e54660f0
    cpe:2.3:a:ash-project:ash_oban:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "collectionURL": "https://repo.hex.pm",
          "cpes": [
            "cpe:2.3:a:ash-project:ash_oban:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "modules": [
            "\u0027Elixir.AshOban\u0027"
          ],
          "packageName": "ash_oban",
          "packageURL": "pkg:hex/ash_oban",
          "product": "ash_oban",
          "programFiles": [
            "lib/ash_oban.ex"
          ],
          "programRoutines": [
            {
              "name": "\u0027Elixir.AshOban\u0027:build_trigger/3"
            }
          ],
          "repo": "https://github.com/ash-project/ash_oban",
          "vendor": "ash-project",
          "versions": [
            {
              "lessThan": "0.8.14",
              "status": "affected",
              "version": "0.2.5",
              "versionType": "semver"
            }
          ]
        },
        {
          "collectionURL": "https://github.com",
          "cpes": [
            "cpe:2.3:a:ash-project:ash_oban:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "modules": [
            "\u0027Elixir.AshOban\u0027"
          ],
          "packageName": "ash-project/ash_oban",
          "packageURL": "pkg:github/ash-project/ash_oban",
          "product": "ash_oban",
          "programFiles": [
            "lib/ash_oban.ex"
          ],
          "programRoutines": [
            {
              "name": "\u0027Elixir.AshOban\u0027:build_trigger/3"
            }
          ],
          "repo": "https://github.com/ash-project/ash_oban",
          "vendor": "ash-project",
          "versions": [
            {
              "lessThan": "da2d81e1e8e1dcc3e6ec8587cdb4f273575ffca3",
              "status": "affected",
              "version": "ce079229ecdf0d323da2b554f30fc569e54660f0",
              "versionType": "git"
            }
          ]
        }
      ],
      "configurations": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eAn application must pass untrusted input into the \u003ccode\u003e:args\u003c/code\u003e option of \u003ccode\u003eAshOban.build_trigger/3\u003c/code\u003e (or an equivalent scheduling helper), on a trigger whose action is an update or destroy, so that an injected \u003ccode\u003eprimary_key\u003c/code\u003e, \u003ccode\u003etenant\u003c/code\u003e, or \u003ccode\u003eaction_arguments\u003c/code\u003e retargets the enqueued job.\u003c/p\u003e"
            },
            {
              "base64": false,
              "type": "text/markdown",
              "value": "An application must pass untrusted input into the `:args` option of `AshOban.build_trigger/3` (or an equivalent scheduling helper), on a trigger whose action is an update or destroy, so that an injected `primary_key`, `tenant`, or `action_arguments` retargets the enqueued job."
            }
          ],
          "value": "An application must pass untrusted input into the :args option of AshOban.build_trigger/3 (or an equivalent scheduling helper), on a trigger whose action is an update or destroy, so that an injected primary_key, tenant, or action_arguments retargets the enqueued job."
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:ash-project:ash_oban:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "0.8.14",
                  "versionStartIncluding": "0.2.5",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ],
          "operator": "AND"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Peter Ullrich"
        },
        {
          "lang": "en",
          "type": "reporter",
          "value": "Peter Ullrich"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "Zach Daniel / Ash Project"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "Jonatan M\u00e4nnchen / EEF"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the \u003ccode\u003e:args\u003c/code\u003e option of \u003ccode\u003eAshOban.build_trigger/3\u003c/code\u003e to retarget an update or destroy trigger at another record, including across tenants.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003ebuild_trigger/3\u003c/code\u003e builds the trusted job arguments with atom keys (\u003ccode\u003e:primary_key\u003c/code\u003e, \u003ccode\u003e:tenant\u003c/code\u003e, \u003ccode\u003e:action_arguments\u003c/code\u003e) and merges the caller\u0027s \u003ccode\u003e:args\u003c/code\u003e underneath so the trusted values win on collision. Because Oban job arguments round-trip through JSON, the caller\u0027s keys arrive as strings, so \u003ccode\u003eMap.merge\u003c/code\u003e sees no collision and both keys survive. When the job is persisted the JSON object is de-duplicated keeping the last (string) key, and the worker reads the caller\u0027s value. The documentation describes \u003ccode\u003e:args\u003c/code\u003e as unable to affect the action, so an application that forwards user input into it for uniqueness scoping is exposed to authorization bypass and tenant isolation breaks.\u003c/p\u003e\n\u003cp\u003eThis issue affects ash_oban: from 0.2.5 before 0.8.14.\u003c/p\u003e"
            },
            {
              "base64": false,
              "type": "text/markdown",
              "value": "Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the `:args` option of `AshOban.build_trigger/3` to retarget an update or destroy trigger at another record, including across tenants.\n\n`build_trigger/3` builds the trusted job arguments with atom keys (`:primary_key`, `:tenant`, `:action_arguments`) and merges the caller\u0027s `:args` underneath so the trusted values win on collision. Because Oban job arguments round-trip through JSON, the caller\u0027s keys arrive as strings, so `Map.merge` sees no collision and both keys survive. When the job is persisted the JSON object is de-duplicated keeping the last (string) key, and the worker reads the caller\u0027s value. The documentation describes `:args` as unable to affect the action, so an application that forwards user input into it for uniqueness scoping is exposed to authorization bypass and tenant isolation breaks.\n\nThis issue affects ash_oban: from 0.2.5 before 0.8.14."
            }
          ],
          "value": "Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to retarget an update or destroy trigger at another record, including across tenants.\n\nbuild_trigger/3 builds the trusted job arguments with atom keys (:primary_key, :tenant, :action_arguments) and merges the caller\u0027s :args underneath so the trusted values win on collision. Because Oban job arguments round-trip through JSON, the caller\u0027s keys arrive as strings, so Map.merge sees no collision and both keys survive. When the job is persisted the JSON object is de-duplicated keeping the last (string) key, and the worker reads the caller\u0027s value. The documentation describes :args as unable to affect the action, so an application that forwards user input into it for uniqueness scoping is exposed to authorization bypass and tenant isolation breaks.\n\nThis issue affects ash_oban: from 0.2.5 before 0.8.14."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-77",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-77 Manipulating User-Controlled Variables"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "LOCAL",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-915",
              "description": "CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-30T11:50:21.136Z",
        "orgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "shortName": "EEF"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "related"
          ],
          "url": "https://github.com/ash-project/ash_oban/security/advisories/GHSA-gj9p-x393-rf9h"
        },
        {
          "tags": [
            "related"
          ],
          "url": "https://cna.erlef.org/cves/CVE-2026-78038.html"
        },
        {
          "tags": [
            "related"
          ],
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-78038"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://github.com/ash-project/ash_oban/commit/da2d81e1e8e1dcc3e6ec8587cdb4f273575ffca3"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "Job argument injection via :args overrides primary_key and tenant in AshOban"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "assignerShortName": "EEF",
    "cveId": "CVE-2026-78038",
    "datePublished": "2026-08-30T11:50:21.136Z",
    "dateReserved": "2026-08-28T19:30:02.318Z",
    "dateUpdated": "2026-08-30T11:50:21.136Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}