EEF-CVE-2026-69659
Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset
Quick fix
EEF-CVE-2026-69659 — ash: upgrade to the fixed version with the command below.
mix deps.update ash Details
## Summary
Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor.
Read actions with keyset pagination deserialize the client-supplied page\[:after\] or page\[:before\] cursor in decode\_values/2 in lib/ash/page/keyset.ex, which base64-decodes the value and passes it to :erlang.binary\_to\_term/2 without bounding its size. The Erlang external term format supports zlib-compressed payloads, which the decoder inflates transparently, so a cursor of a few kilobytes can allocate tens of megabytes of heap in a single call. Ash itself only ever encodes cursors uncompressed, so the decoder accepts a term shape its encoder never produces. Concurrent requests aggregate these allocations and can terminate the node.
This issue affects ash: from 1.17.0 before 3.31.1.
## Configuration
A read action must declare keyset? true in its pagination block, and the application must pass a client-supplied value as the :after or :before page option.
Are you affected?
Enter the version of the package you're using.