Summary
CVE-2026-94201 is a denial-of-service vulnerability in the Ash Framework, a data layer and application framework for Elixir, caused by uncontrolled atom creation when filtering on :atom-typed resource attributes. An unauthenticated or low-privileged remote actor who can supply filter values to a public, filterable atom attribute can force the application to permanently exhaust the BEAM virtual machine’s finite atom table, crashing the node. The issue carries a CVSS score of 8.2 (High) and affects Ash versions 3.5.1 through 3.34.2.
Technical details
- Root cause:
Ash.Type.Atomdid not implement acoerce/2callback. When an attacker-controlled value was filtered against an atom attribute configured withunsafe_to_atom?: true, Ash’s filter-coercion path fell back tocast_input/2, which calls Elixir’sString.to_atom/1. - Why it’s dangerous: In the BEAM (Erlang VM) runtime, atoms are never garbage collected and the atom table has a fixed maximum size. Calling
String.to_atom/1on attacker-supplied, non-repeating strings permanently interns a new atom for every distinct filter value submitted. - Trigger conditions: A resource must expose a public, filterable
:atomattribute with theunsafe_to_atom?: trueconstraint, reachable through a query interface such as AshGraphql, AshJsonApi, orAsh.Query.filter_input/2. - Notably exposed component: AshPaperTrail version resources are especially at risk, since their default
version_action_nameattribute is an atom attribute configured withunsafe_to_atom?: trueout of the box. - Attack vector: Network — no authentication beyond the ability to submit filter parameters is required, and no user interaction is needed.
- Impact: Repeated submission of unique filter values exhausts the BEAM atom table, ultimately crashing the Erlang VM and taking down the entire application node (availability impact only; no confidentiality or integrity impact).
Affected software
- Package:
ash(Hex/Elixir), vendorash-project - Vulnerable versions: 3.5.1 through 3.34.2
- Fixed version: 3.34.3 and later
- Affected module:
Ash.Type.Atom(lib/ash/type/atom.ex) - Applications using Ash resources with public, filterable
:atomattributes configured withunsafe_to_atom?: true(including deployments using AshPaperTrail’s default version resource configuration) are at heightened risk.
Severity
- CVSS Score: 8.2 (High)
- CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N - CWE-770: Allocation of Resources Without Limits or Throttling
Mitigation and recommended actions
- Immediate: Upgrade
ashto version 3.34.3 or later, which adds acoerce/2callback toAsh.Type.Atomthat avoids interning new atoms during filtering while preserving existingunsafe_to_atom?behavior for direct attribute assignment. - If immediate patching is not possible:
- Audit resources for public, filterable
:atomattributes withunsafe_to_atom?: true, and restrict or remove filter access on these attributes until patched. - Pay particular attention to AshPaperTrail-generated version resources, which expose this configuration by default.
- Monitor BEAM atom table usage/consumption metrics and application availability for signs of exploitation attempts.
- Audit resources for public, filterable

