Threadlinqs IntelligenceStart free

Vendor4 products tracked

ash-project vulnerabilities & exploitation

As of 2026-10-05, Threadlinqs tracks 9 ash-project CVEs, 0 in the CISA Known Exploited Vulnerabilities catalog, linked to 0 tracked threat campaigns.

CVEs
9Since 2026
CISA KEV
00% of CVEs
Critical
0CVSS v3 9.0+
Avg CVSS
6.3/10Max 8.2
Threats
0None linked yet
Actors
0None attributed

Data as of:

Exploitation timeline

Threadlinqs has recorded 9 ash-project CVEs published between and . The busiest month was 2026-09 (7 new CVEs). None of them is listed in CISA KEV yet.

Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 9 of 9 tracked ash-project CVEs.

Products affected

Threadlinqs normalises CPE and CNA product records across all 9 CVEs; 4 distinct ash-project products are affected. The most frequently affected:

  • ash_authentication_oauth2_server 6 CVEs
  • ash 1 CVE
  • ash_graphql 1 CVE
  • ash_lua 1 CVE

Threat activity

No tracked threat campaign references ash-project products or CVEs yet. Vulnerability records are still monitored for exploitation and linked as campaigns are ingested.

How to prioritise ash-project patching

This order follows the data Threadlinqs holds for ash-project, not a generic severity checklist:

  • No ash-project CVE is in CISA KEV yet, so rank by exploit probability instead.
  • Outside KEV, the highest EPSS scores are CVE-2026-82753 (0.4%), CVE-2026-82754 (0.4%), CVE-2026-82758 (0.4%).
  • 0 CVEs score Critical and 3 High on CVSS v3 (maximum 8.2, average 6.3); sequence these after KEV and high-EPSS items.

About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.