# CVE-2026-82727

## Summary

- **CVE ID:** CVE-2026-82727
- **Severity:** LOW
- **CVSS Score:** 2.3 (CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-209
- **Published:** Aug 31, 2026
- **Last Modified:** Aug 31, 2026

## Description

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_phoenix writes the entire raw submitted param map into an exception message, so secrets submitted alongside a union form field leak into logs, crash reports and the dev error page.

When AshPhoenix.Form.Auto builds a union sub-form and the submitted _union_type does not match a configured type, both raise sites built the message with inspect(params, pretty: true), embedding the full untrusted param map, and also inspected the internal union constraints[:types]. Because the message is constructed by the library rather than Phoenix's parameter logger, config :phoenix, :filter_parameters never redacts it. An attacker controls both the trigger and the contents: submitting %{"_union_type" => "nope", "password" => "..."} puts the password verbatim in the raised message. The fix reports only the offending _union_type and the valid type names, dropping the param and constraints dumps.

This issue affects ash_phoenix: from 1.2.17 before 2.3.25.

## Affected Products

- ash-project — ash_phoenix (1.2.17)
- ash-project — ash_phoenix (a3436fcc321e3b34c242cceaf62c3c92bc1a452b)

## References

- [CNA](https://github.com/ash-project/ash_phoenix/security/advisories/GHSA-5xf4-hgcq-xw7v)
- [CNA](https://cna.erlef.org/cves/CVE-2026-82727.html)
- [CNA](https://osv.dev/vulnerability/EEF-CVE-2026-82727)
- [CNA](https://github.com/ash-project/ash_phoenix/commit/0c1775c3cf8988f9abd10a8f92315afc5f06f16d)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.27%
- **EPSS Percentile:** 18.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._