CVE-2026-67579 | ash-project ash up to 3.31.2 Keyset Pagination lib/ash/page/keyset.ex decode_values after/before sql injection
A vulnerability was found in ash-project ash up to 3.31.2 and classified as critical. This affects the function decode_values of the file lib/ash/page/keyset.ex of the component Keyset Pagination. The manipulation of the argument after/before results in sql injection.
This vulnerability is reported as CVE-2026-67579. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More