EEF-CVE-2026-80227
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Quick fix
EEF-CVE-2026-80227 — ash_sql: upgrade to the fixed version with the command below.
mix deps.update ash_sqlDetails
## Summary
Incorrect Comparison vulnerability in ash-project ash\_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).
string\_trim/1 compiles to REGEXP\_REPLACE patterns built from an Elixir string in which \\s is the escape for a single space (codepoint 32), not a regex whitespace class. The generated SQL therefore removes only literal spaces and leaves tabs, newlines, carriage returns, and form feeds in place, whereas String.trim/1 in Elixir removes them all. Any Ash filter, validation, or identity that relies on string\_trim/1 then behaves differently depending on whether Ash pushes the expression down to SQL or evaluates it in memory, so padded input can register a near-duplicate value or slip past a trimmed comparison.
This issue affects ash\_sql: from 0.1.0 before 0.7.1.
## Configuration
An application must use string\_trim/1 in a filter, validation, calculation, or identity that an attacker-influenced string field flows through, where the trimmed value is compared for equality or uniqueness.
Are you affected?
Enter the version of the package you're using.