THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-78228 — Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to fail on the final attempt to exhaust worker CPU and memory, denying service. The generated worker's atomic handle_error/4 runs the trigger's on_error action on

[NVD] CVE-2026-78228 — Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to fail on the final attempt to exhaust worker CPU and memory, denying service. The generated worker's atomic handle_error/4 runs the trigger's on_error action on

mednvdPublished 2026-08-30

CVE-2026-78228 CVSS: None Published: 2026-08-30T12:17:18.380

Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to fail on the final attempt to exhaust worker CPU and memory, denying service.

The generated worker's atomic handle_error/4 runs the trigger's on_error action on a job's final attempt inside a rescue that, when the act

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-78228