CVE-2026-80227CWE-697

CVE-2026-80227

published August 30, 2026

CVSS
2.1
EPSS
0%
Percentile
17.3
In the wild
Unconfirmed
What it is

Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse).

string_trim/1 compiles to REGEXP_REPLACE patterns built from an Elixir string in which \s is the escape for a single space (codepoint 32), not a regex whitespace class. The generated SQL therefore removes only literal spaces and leaves tabs, newlines, carriage returns, and form feeds in place, whereas String.trim/1 in Elixir removes them all. Any Ash filter, validation, or identity that relies on string_trim/1 then behaves differently depending on whether Ash pushes the expression down to SQL or evaluates it in memory, so padded input can register a near-duplicate value or slip past a trimmed comparison.

This issue affects ash_sql: from 0.1.0 before 0.7.1.

The record
Technical detail
CVSS
2.1 · NONE
CVSS v4.0
2.1 · CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS
0.00257 · 17.3th percentile
Weakness
CWE-697 · Incorrect Comparison
Published
2026-08-30T16:17Z
References (5)
EPSS history
Timeline
  • 01 SEP 03:31Z
    EPSS moved — → 0%
    epss
  • 30 AUG 11:53Z
    SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
    cvelistv5