CyberRota Analysis
AI-GeneratedThe vulnerability in ash_typescript allows unauthenticated attackers to exploit the allocation of resources by supplying arbitrary field names, leading to the exhaustion of the BEAM atom table and potential node crashes. This can result in denial of service, as the system becomes unresponsive when the atom table limit is reached. Organizations using ash_typescript versions from 0.11.0 to before 0.18.0 should prioritize patching this vulnerability to safeguard against potential service disruptions.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied typed struct field names. resolve_typed_struct_field/2 in lib/ash_typescript/rpc/field_processing/field_selector.ex looks a client-supplied field name up in the typed struct's reverse map and, when it finds no match, falls back to String.to_atom/1. Because this runs before any field-existence check, an unresolvable name mints a permanent atom rather than being rejected as unknown. Atoms are never garbage collected, so a request carrying many distinct names on a typed struct field grows the atom table until the VM aborts at its limit. This issue affects ash_typescript: from 0.11.0 before 0.18.0.