VDB
Sign up
—

EEF-CVE-2026-69659

Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset

Quick fix

EEF-CVE-2026-69659 — ash: upgrade to the fixed version with the command below.

mix deps.update ash

Details

## Summary

Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor.

Read actions with keyset pagination deserialize the client-supplied `page[:after]` or `page[:before]` cursor in `decode_values/2` in `lib/ash/page/keyset.ex`, which base64-decodes the value and passes it to `:erlang.binary_to_term/2` without bounding its size. The Erlang external term format supports zlib-compressed payloads, which the decoder inflates transparently, so a cursor of a few kilobytes can allocate tens of megabytes of heap in a single call. Ash itself only ever encodes cursors uncompressed, so the decoder accepts a term shape its encoder never produces. Concurrent requests aggregate these allocations and can terminate the node.

This issue affects ash: from 1.17.0 before 3.31.1.

## Configurations

A read action must declare `keyset? true` in its `pagination` block, and the application must pass a client-supplied value as the `:after` or `:before` page option.

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex/ash
Introduced in: 1.17.0Fixed in: 3.31.1
Fixmix deps.update ash

References