VDB
Sign up

EEF-CVE-2026-80227

SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql

Quick fix

EEF-CVE-2026-80227 — ash_sql: upgrade to the fixed version with the command below.

mix deps.update ash_sql

Details

## Summary

Incorrect Comparison vulnerability in ash-project ash\_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).

string\_trim/1 compiles to REGEXP\_REPLACE patterns built from an Elixir string in which \\s is the escape for a single space (codepoint 32), not a regex whitespace class. The generated SQL therefore removes only literal spaces and leaves tabs, newlines, carriage returns, and form feeds in place, whereas String.trim/1 in Elixir removes them all. Any Ash filter, validation, or identity that relies on string\_trim/1 then behaves differently depending on whether Ash pushes the expression down to SQL or evaluates it in memory, so padded input can register a near-duplicate value or slip past a trimmed comparison.

This issue affects ash\_sql: from 0.1.0 before 0.7.1.

## Configuration

An application must use string\_trim/1 in a filter, validation, calculation, or identity that an attacker-influenced string field flows through, where the trimmed value is compared for equality or uniqueness.

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex/ash_sql
Introduced in: 0.1.0Fixed in: 0.7.1
Fixmix deps.update ash_sql

References