Stack-trace disclosure via unvalidated relay type
Published Aug 30, 2026 · Updated Aug 30, 2026
Improper input validation in Ash Framework AshGraphql 0.27.0 through 1.10.1 allows remote attackers to crash relay node queries. resolve_node/2 base64-decodes and splits the supplied global ID without validating its type segment, then passes that segment to Map.fetch!, which raises on an unmapped atom. An application must expose the AshGraphql relay node field over HTTP; exploitation requires no authentication and interrupts only the request while disclosing error details.
Summary
What happened
Improper input validation in Ash Framework AshGraphql 0.27.0 through 1.10.1 allows remote attackers to crash relay node queries. resolve_node/2 base64-decodes and splits the supplied global ID without validating its type segment, then passes that segment to Map.fetch!, which raises on an unmapped atom. An application must expose the AshGraphql relay node field over HTTP; exploitation requires no authentication and interrupts only the request while disclosing error details.
The record
- CVE
- CVE-2026-81633
- Published
- Aug 30, 2026
- Updated
- Aug 30, 2026
- Vendor
- Ash Framework
- Product
- AshGraphql
- Classifications
- CWE-20, CAPEC-153, T1190
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Aug 30, 2026CVE publishedPublication date reported by the CVE source.
- Aug 30, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0.27.0 <1.11.0
- Affected versionversion=365b3aedc6b36f020e6a2c7dce63fa569243bc4e <c8863ed8e5c21f1bfb6125f1d24e78443dfc6351
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- AshGraphql relay node HTTP proof of conceptproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo