security1 distinct publisher
CVE-2026-77846 lets one attacker-supplied dot walk AshSqlite's JSON query into private fields
The Erlang Ecosystem Foundation's CNA published the entry on August 30, 2026, and ash_sqlite 0.2.18 escapes the path segments. Exposure comes down to whether your callers get to name the JSON field.
Publishers:thecyberexpress.com
Reality
- Evidence64
- Adoption18
- Hype gap−6
- Incentives30