SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81319

MEDIUM · CVSS 5.9 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-30 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The ash_cloak library is vulnerable to a deserialization of untrusted data issue that allows attackers to influence encrypted column bytes, potentially leading to a crash of the BEAM node through unbounded atom creation or decompression bomb exploitation. This vulnerability primarily affects versions from 0.1.0 to before 0.4.0, and organizations using these versions should prioritize remediation to prevent service disruptions and potential denial-of-service scenarios. Users relying on ash_cloak for secure data handling should assess their implementations and upgrade to a patched version to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81319
Severity
MEDIUM
CVSS
5.9
EPSS
0.23%

Original NVD Description

Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes of an encrypted column to crash the BEAM node, by triggering unbounded atom creation or a decompression bomb during decryption. AshCloak.Calculations.Decrypt decodes the decrypted binary with Ash.Helpers.non_executable_binary_to_term/1 without the :safe option, so atoms in the payload are interned during the decode and never garbage collected, and the term format's compressed form is inflated transparently. vault.decrypt!() is the only barrier and stops tampering only for an authenticated cipher. Cloak also ships the unauthenticated AES.CTR, whose ciphertext an attacker who knows their own plaintext can XOR into any same-length payload without the key, so an ordinary read of the forged column reaches the decoder. A few hundred kilobytes of distinct atoms exhausts the atom table, or a small compressed payload inflates to gigabytes. This issue affects ash_cloak: from 0.1.0 before 0.4.0.