SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82735

MEDIUM · CVSS 5.9 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows attackers to exploit a flaw in the ash-project's string handling, where an expensive regular expression can be executed on input that should have been rejected based on length constraints. This can lead to excessive CPU consumption and potential denial-of-service conditions when processing malicious input. Organizations using affected versions of ash (from 0.10.0 to before 3.32.2) should prioritize patching to mitigate the risk of resource exhaustion attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82735
Severity
MEDIUM
CVSS
5.9
EPSS
0.14%

Original NVD Description

Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to force an expensive regular expression to run on input that a length constraint should have already rejected. Ash.Type.String.apply_constraints/2 (lib/ash/type/string.ex) evaluated the :match regex regardless of the min_length and max_length constraints on the same attribute. Because the length check did not gate the regex, an over-length value that the length constraint rejects still had the pattern applied to it, so the length limit that would otherwise bound the work never constrained the regex input. Against a backtracking pattern this yields catastrophic regex evaluation on attacker-sized input, and even a linear pattern runs on arbitrarily large input, consuming CPU per request. The fix skips the :match regex whenever a length constraint is violated, making the two checks order-independent. This issue affects ash: from 0.10.0 before 3.32.2.