VDB
KO

EEF-CVE-2026-69659

Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset

Quick fix

EEF-CVE-2026-69659 — ash: upgrade to the fixed version with the command below.

mix deps.update ash

Details

## Summary

Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor.

Read actions with keyset pagination deserialize the client-supplied page\[:after\] or page\[:before\] cursor in decode\_values/2 in lib/ash/page/keyset.ex, which base64-decodes the value and passes it to :erlang.binary\_to\_term/2 without bounding its size. The Erlang external term format supports zlib-compressed payloads, which the decoder inflates transparently, so a cursor of a few kilobytes can allocate tens of megabytes of heap in a single call. Ash itself only ever encodes cursors uncompressed, so the decoder accepts a term shape its encoder never produces. Concurrent requests aggregate these allocations and can terminate the node.

This issue affects ash: from 1.17.0 before 3.31.1.

## Configuration

A read action must declare keyset? true in its pagination block, and the application must pass a client-supplied value as the :after or :before page option.

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex / ash
Introduced in: 1.17.0 Fixed in: 3.31.1
Fix mix deps.update ash

References