CVE-2026-81638
CVE-2026-81638 is a low-severity vulnerability with a CVSS 4.0 base score of 2.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-173.
Key facts
- Severity: Low (CVSS 4.0 base score 2.1)
- EPSS exploit prediction: 0% (8th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-173
- Published:
- Last modified:
Description
Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier. AshDoubleEntry.ULID renders a 128-bit ULID as 26 Crockford base-32 characters, but the first character encodes only 3 bits, so canonical values are 0 to 7. decode/1 in lib/ulid.ex masks the first character to its low 3 bits and valid?/1 accepts all 32 characters in that position, so 0..., 8..., G... and R... decode to the identical 16-byte value and resolve to the same row. When the type is exposed as a public ID over an HTTP or API boundary, an attacker-supplied ID can be spelled differently from the record it actually reads or writes, desynchronizing or bypassing string-level checks such as idempotency and deduplication keys, deny-lists, audit correlation, or signatures computed over the submitted ID. This issue affects ash_double_entry: from 0.1.0 before 1.0.19.
Frequently asked questions
- What is CVE-2026-81638?
- Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier. AshDoubleEntry.ULID renders a 128-bit ULID as 26 Crockford base-32 characters, but the first character encodes only 3 bits, so canonical values are 0 to 7. decode/1 in lib/ulid.ex masks the first character to its low 3 bits and valid?/1 accepts all 32 characters in that position, so 0..., 8..., G... and R... decode to the identical 16-byte value and resolve to the same row. When the type is exposed as a public ID over an HTTP or API boundary, an attacker-supplied ID can be spelled differently from the record it actually reads or writes, desynchronizing or bypassing string-level checks such as idempotency and deduplication keys, deny-lists, audit correlation, or signatures computed over the submitted ID. This issue affects ash_double_entry: from 0.1.0 before 1.0.19.
- How severe is CVE-2026-81638?
- CVE-2026-81638 has a CVSS 4.0 base score of 2.1, rated low severity.
- Is CVE-2026-81638 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (8th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-81638?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-81638 published?
- CVE-2026-81638 was published on 2026-09-07 and last updated on 2026-09-08.
References
- https://cna.erlef.org/cves/CVE-2026-81638.html
- https://github.com/ash-project/ash_double_entry/commit/d3e688d300a581ae214b3ca7d95ef4de63fbb050
- https://github.com/ash-project/ash_double_entry/security/advisories/GHSA-qxp2-vgp9-268q
- https://osv.dev/vulnerability/EEF-CVE-2026-81638
Other CWE-173 vulnerabilities
- CVE-2026-10050 — Critical (CVSS 9.1): In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as…
- CVE-2026-19611 — High (CVSS 7.4): A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can…
- CVE-2026-103276 — Medium (CVSS 5.3): Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated…
- CVE-2023-26303 — Low (CVSS 3.3): Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions…
- CVE-2023-26302 — Low (CVSS 3.3): Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was…