Description
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied typed struct field names.

resolve_typed_struct_field/2 in lib/ash_typescript/rpc/field_processing/field_selector.ex looks a client-supplied field name up in the typed struct's reverse map and, when it finds no match, falls back to String.to_atom/1. Because this runs before any field-existence check, an unresolvable name mints a permanent atom rather than being rejected as unknown. Atoms are never garbage collected, so a request carrying many distinct names on a typed struct field grows the atom table until the VM aborts at its limit.

This issue affects ash_typescript: from 0.11.0 before 0.18.0.
Published: 2026-09-01
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when the AshTypescript field selector resolves typed struct field names for incoming RPC messages. If a client supplies a field name that does not exist in the struct's reverse map, the resolver falls back to the BEAM function String.to_atom/1. Because atoms are immutable and never garbage collected, each request that contains an unknown field name results in a new atom being permanently added. Repeated use of distinct unknown field names can exhaust the BEAM atom table, causing the Erlang virtual machine to terminate and abort the node. The flaw allows an unauthenticated attacker to trigger large numbers of unique atoms through crafted requests, leading to denial of service.

Affected Systems

The affected product is AshProject’s AshTypescript, a library used for typed struct field selection in Erlang/Elixir applications. Vulnerable releases are those that include the unbounded atom creation logic, specifically versions from 0.11.0 up to but not including 0.18.0. Any application that depends on these versions of AshTypescript and exposes an RPC endpoint that passes user-controlled field names is at risk.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. The EPSS score is not available, but the lack of an official KEV listing does not diminish the impact for systems that expose the vulnerable interface. The attack can be carried out remotely via the RPC interface without authentication. An attacker can overwhelm the atom table by sending a large volume of distinct field names, ultimately causing the node to crash and lead to service interruption. The exploit requires only network access to the exposed endpoint and no privileged credentials, making it a high risk for publicly accessible nodes.

Generated by OpenCVE AI on September 1, 2026 at 03:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade AshTypescript to version 0.18.0 or later, where the atom creation logic is guarded by a field‑existence check.
  • If upgrading is not immediately possible, implement a whitelist for acceptable field names: validate incoming field names against the struct's subset before converting to atom.
  • Monitor the atom table size on the BEAM VM; if usage approaches the operational limit, trigger automated restart or throttling of incoming RPC requests.
  • Consider disabling or restricting the RPC endpoint that accepts user‑supplied struct field names if it is not required for the application.

Generated by OpenCVE AI on September 1, 2026 at 03:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied typed struct field names. resolve_typed_struct_field/2 in lib/ash_typescript/rpc/field_processing/field_selector.ex looks a client-supplied field name up in the typed struct's reverse map and, when it finds no match, falls back to String.to_atom/1. Because this runs before any field-existence check, an unresolvable name mints a permanent atom rather than being rejected as unknown. Atoms are never garbage collected, so a request carrying many distinct names on a typed struct field grows the atom table until the VM aborts at its limit. This issue affects ash_typescript: from 0.11.0 before 0.18.0.
Title Unbounded atom creation from typed struct field names in AshTypescript field selector
First Time appeared Ash-project
Ash-project ash Typescript
Weaknesses CWE-770
CPEs cpe:2.3:a:ash-project:ash_typescript:*:*:*:*:*:*:*:*
Vendors & Products Ash-project
Ash-project ash Typescript
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Ash-project Ash Typescript
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-01T02:08:46.189Z

Reserved: 2026-08-30T17:30:01.406Z

Link: CVE-2026-77856

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T03:16:51.500

Modified: 2026-09-01T03:16:51.500

Link: CVE-2026-77856

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T03:30:04Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling