AshAi.ToolLoop classifies a model response of :tool_calls, then filters the calls through normalize_tool_calls/2 and unprocessed_tool_calls/2. Both can empty the list: a call missing a valid name, or one reusing a tool_call_id that already has a result in history, is dropped. With an empty list the loop appended nothing and recursed with a byte-identical message list, so the conversation never advanced and the same request was re-sent every iteration. Under the supported max_iterations: :infinity this never terminated; otherwise it exhausted the full budget. Prompt-injected content can make the model re-emit a spent tool_call_id. The fix treats an empty post-filter list as terminal.
This issue affects ash_ai: from 0.6.0 before 1.0.0.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a model response of :tool_calls, then filters the calls through normalize_tool_calls/2 and unprocessed_tool_calls/2. Both can empty the list: a call missing a valid name, or one reusing a tool_call_id that already has a result in history, is dropped. With an empty list the loop appended nothing and recursed with a byte-identical message list, so the conversation never advanced and the same request was re-sent every iteration. Under the supported max_iterations: :infinity this never terminated; otherwise it exhausted the full budget. Prompt-injected content can make the model re-emit a spent tool_call_id. The fix treats an empty post-filter list as terminal. This issue affects ash_ai: from 0.6.0 before 1.0.0. | |
| Title | AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service | |
| First Time appeared |
Ash-project
Ash-project ash Ai |
|
| Weaknesses | CWE-835 | |
| CPEs | cpe:2.3:a:ash-project:ash_ai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ash-project
Ash-project ash Ai |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-08-31T01:07:49.185Z
Reserved: 2026-08-30T20:00:01.852Z
Link: CVE-2026-82579
No data.
Status : Received
Published: 2026-08-31T02:17:02.270
Modified: 2026-08-31T02:17:02.270
Link: CVE-2026-82579
No data.
OpenCVE Enrichment
Updated: 2026-08-31T02:30:18Z
-
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')