{"meta":{"links":{"Changelog":"https://github.com/team-alembic/ash_authentication/blob/main/CHANGELOG.md","Phoenix Support":"https://github.com/team-alembic/ash_authentication_phoenix","REUSE Compliance":"https://api.reuse.software/info/github.com/team-alembic/ash_authentication","Source":"https://github.com/team-alembic/ash_authentication"},"description":"Authentication extension for the Ash Framework.","licenses":["MIT"],"maintainers":[]},"name":"ash_authentication","url":"https://hex.pm/api/packages/ash_authentication","owners":[{"url":"https://hex.pm/api/users/ash-project","email":"ash-project@zachdaniel.dev","username":"ash-project"},{"url":"https://hex.pm/api/users/jamesotron","email":"james@harton.nz","username":"jamesotron"},{"url":"https://hex.pm/api/users/joshcprice","username":"joshcprice"}],"inserted_at":"2022-12-08T02:37:59.387153Z","updated_at":"2026-09-17T00:14:15.509104Z","repository":"hexpm","releases":[{"version":"5.0.0-rc.14","url":"https://hex.pm/api/packages/ash_authentication/releases/5.0.0-rc.14","has_docs":true,"inserted_at":"2026-09-17T00:03:12.782427Z"},{"version":"5.0.0-rc.13","url":"https://hex.pm/api/packages/ash_authentication/releases/5.0.0-rc.13","has_docs":true,"inserted_at":"2026-08-25T04:31:15.025138Z"},{"version":"5.0.0-rc.12","url":"https://hex.pm/api/packages/ash_authentication/releases/5.0.0-rc.12","has_docs":true,"inserted_at":"2026-07-08T03:52:19.399907Z"},{"version":"5.0.0-rc.11","url":"https://hex.pm/api/packages/ash_authentication/releases/5.0.0-rc.11","has_docs":true,"inserted_at":"2026-06-15T04:39:51.109041Z"},{"version":"5.0.0-rc.10","url":"https://hex.pm/api/packages/ash_authentication/releases/5.0.0-rc.10","has_docs":true,"inserted_at":"2026-06-15T00:22:36.104399Z"},{"version":"5.0.0-rc.9","url":"https://hex.pm/api/packages/ash_authentication/releases/5.0.0-rc.9","has_docs":true,"inserted_at":"2026-05-11T00:34:07.590992Z"},{"version":"5.0.0-rc.8","url":"https://hex.pm/api/packages/ash_authentication/releases/5.0.0-rc.8","has_docs":true,"inserted_at":"2026-05-08T01:47:17.044623Z"},{"version":"5.0.0-rc.7","url":"https://hex.pm/api/packages/ash_authentication/releases/5.0.0-rc.7","has_docs":true,"inserted_at":"2026-05-04T03:45:08.953010Z"},{"version":"5.0.0-rc.6","url":"https://hex.pm/api/packages/ash_authentication/releases/5.0.0-rc.6","has_docs":true,"inserted_at":"2026-05-04T03:29:31.227421Z"},{"version":"5.0.0-rc.5","url":"https://hex.pm/api/packages/ash_authentication/releases/5.0.0-rc.5","has_docs":true,"inserted_at":"2026-04-30T00:57:46.385398Z"},{"version":"5.0.0-rc.4","url":"https://hex.pm/api/packages/ash_authentication/releases/5.0.0-rc.4","has_docs":true,"inserted_at":"2026-04-30T00:20:36.878477Z"},{"version":"5.0.0-rc.3","url":"https://hex.pm/api/packages/ash_authentication/releases/5.0.0-rc.3","has_docs":true,"inserted_at":"2026-04-13T22:52:46.269891Z"},{"version":"5.0.0-rc.2","url":"https://hex.pm/api/packages/ash_authentication/releases/5.0.0-rc.2","has_docs":true,"inserted_at":"2026-04-12T23:11:16.960960Z"},{"version":"5.0.0-rc.1","url":"https://hex.pm/api/packages/ash_authentication/releases/5.0.0-rc.1","has_docs":true,"inserted_at":"2026-02-09T22:51:07.739994Z"},{"version":"5.0.0-rc.0","url":"https://hex.pm/api/packages/ash_authentication/releases/5.0.0-rc.0","has_docs":true,"inserted_at":"2026-01-27T23:11:33.314146Z"},{"version":"4.15.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.15.0","has_docs":true,"inserted_at":"2026-09-17T00:14:14.011532Z"},{"version":"4.14.2","url":"https://hex.pm/api/packages/ash_authentication/releases/4.14.2","has_docs":true,"inserted_at":"2026-08-25T04:52:59.881874Z"},{"version":"4.14.1","url":"https://hex.pm/api/packages/ash_authentication/releases/4.14.1","has_docs":true,"inserted_at":"2026-06-15T04:39:39.527061Z"},{"version":"4.14.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.14.0","has_docs":true,"inserted_at":"2026-06-14T22:57:00.382618Z"},{"version":"4.13.7","url":"https://hex.pm/api/packages/ash_authentication/releases/4.13.7","has_docs":true,"inserted_at":"2026-01-13T02:03:10.954154Z"},{"version":"4.13.6","url":"https://hex.pm/api/packages/ash_authentication/releases/4.13.6","has_docs":true,"inserted_at":"2026-01-04T22:51:10.921422Z"},{"version":"4.13.5","url":"https://hex.pm/api/packages/ash_authentication/releases/4.13.5","has_docs":true,"inserted_at":"2026-01-04T21:56:42.851297Z"},{"version":"4.13.4","url":"https://hex.pm/api/packages/ash_authentication/releases/4.13.4","has_docs":true,"inserted_at":"2025-12-12T22:57:49.338758Z"},{"version":"4.13.3","url":"https://hex.pm/api/packages/ash_authentication/releases/4.13.3","has_docs":true,"inserted_at":"2025-12-01T02:05:31.313203Z"},{"version":"4.13.2","url":"https://hex.pm/api/packages/ash_authentication/releases/4.13.2","has_docs":true,"inserted_at":"2025-11-30T21:53:43.830419Z"},{"version":"4.13.1","url":"https://hex.pm/api/packages/ash_authentication/releases/4.13.1","has_docs":true,"inserted_at":"2025-11-28T01:04:32.439555Z"},{"version":"4.13.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.13.0","has_docs":true,"inserted_at":"2025-11-17T18:48:48.404404Z"},{"version":"4.12.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.12.0","has_docs":true,"inserted_at":"2025-10-20T22:52:11.595849Z"},{"version":"4.11.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.11.0","has_docs":true,"inserted_at":"2025-10-08T01:17:57.260937Z"},{"version":"4.10.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.10.0","has_docs":true,"inserted_at":"2025-09-11T13:14:33.657099Z"},{"version":"4.9.9","url":"https://hex.pm/api/packages/ash_authentication/releases/4.9.9","has_docs":true,"inserted_at":"2025-07-29T21:23:28.993898Z"},{"version":"4.9.8","url":"https://hex.pm/api/packages/ash_authentication/releases/4.9.8","has_docs":true,"inserted_at":"2025-07-22T15:09:50.363395Z"},{"version":"4.9.7","url":"https://hex.pm/api/packages/ash_authentication/releases/4.9.7","has_docs":true,"inserted_at":"2025-07-17T15:39:07.351880Z"},{"version":"4.9.6","url":"https://hex.pm/api/packages/ash_authentication/releases/4.9.6","has_docs":true,"inserted_at":"2025-07-11T02:39:18.442190Z"},{"version":"4.9.5","url":"https://hex.pm/api/packages/ash_authentication/releases/4.9.5","has_docs":true,"inserted_at":"2025-07-02T14:19:17.207765Z"},{"version":"4.9.4","url":"https://hex.pm/api/packages/ash_authentication/releases/4.9.4","has_docs":true,"inserted_at":"2025-06-19T13:34:09.527808Z"},{"version":"4.9.3","url":"https://hex.pm/api/packages/ash_authentication/releases/4.9.3","has_docs":true,"inserted_at":"2025-06-18T23:51:12.542655Z"},{"version":"4.9.2","url":"https://hex.pm/api/packages/ash_authentication/releases/4.9.2","has_docs":true,"inserted_at":"2025-06-17T04:07:15.647732Z"},{"version":"4.9.1","url":"https://hex.pm/api/packages/ash_authentication/releases/4.9.1","has_docs":true,"inserted_at":"2025-06-16T22:34:27.056151Z"},{"version":"4.9.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.9.0","has_docs":true,"inserted_at":"2025-05-30T18:59:59.184491Z"},{"version":"4.8.7","url":"https://hex.pm/api/packages/ash_authentication/releases/4.8.7","has_docs":true,"inserted_at":"2025-05-20T14:37:20.676699Z"},{"version":"4.8.6","url":"https://hex.pm/api/packages/ash_authentication/releases/4.8.6","has_docs":true,"inserted_at":"2025-05-16T00:13:18.305210Z"},{"version":"4.8.5","url":"https://hex.pm/api/packages/ash_authentication/releases/4.8.5","has_docs":true,"inserted_at":"2025-05-15T06:27:35.105339Z"},{"version":"4.8.3","url":"https://hex.pm/api/packages/ash_authentication/releases/4.8.3","has_docs":true,"inserted_at":"2025-05-09T11:28:18.431692Z"},{"version":"4.8.2","url":"https://hex.pm/api/packages/ash_authentication/releases/4.8.2","has_docs":true,"inserted_at":"2025-05-07T04:18:56.170448Z"},{"version":"4.8.1","url":"https://hex.pm/api/packages/ash_authentication/releases/4.8.1","has_docs":true,"inserted_at":"2025-05-07T03:35:45.067977Z"},{"version":"4.8.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.8.0","has_docs":true,"inserted_at":"2025-05-07T02:57:56.641158Z"},{"version":"4.7.6","url":"https://hex.pm/api/packages/ash_authentication/releases/4.7.6","has_docs":true,"inserted_at":"2025-04-16T00:17:01.137887Z"},{"version":"4.7.5","url":"https://hex.pm/api/packages/ash_authentication/releases/4.7.5","has_docs":true,"inserted_at":"2025-04-15T18:15:03.971199Z"},{"version":"4.7.4","url":"https://hex.pm/api/packages/ash_authentication/releases/4.7.4","has_docs":true,"inserted_at":"2025-04-15T12:06:12.742578Z"},{"version":"4.7.3","url":"https://hex.pm/api/packages/ash_authentication/releases/4.7.3","has_docs":true,"inserted_at":"2025-04-15T00:59:33.234302Z"},{"version":"4.7.2","url":"https://hex.pm/api/packages/ash_authentication/releases/4.7.2","has_docs":true,"inserted_at":"2025-04-14T23:14:23.636494Z"},{"version":"4.7.1","url":"https://hex.pm/api/packages/ash_authentication/releases/4.7.1","has_docs":true,"inserted_at":"2025-04-14T22:13:48.537812Z"},{"version":"4.7.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.7.0","has_docs":true,"inserted_at":"2025-04-14T21:48:35.776575Z"},{"version":"4.6.4","url":"https://hex.pm/api/packages/ash_authentication/releases/4.6.4","has_docs":true,"inserted_at":"2025-04-09T23:21:48.513626Z"},{"version":"4.6.3","url":"https://hex.pm/api/packages/ash_authentication/releases/4.6.3","has_docs":true,"inserted_at":"2025-03-27T15:02:03.971395Z"},{"version":"4.6.2","url":"https://hex.pm/api/packages/ash_authentication/releases/4.6.2","has_docs":true,"inserted_at":"2025-03-25T16:30:40.810928Z"},{"version":"4.6.1","url":"https://hex.pm/api/packages/ash_authentication/releases/4.6.1","has_docs":true,"inserted_at":"2025-03-25T15:08:43.560691Z"},{"version":"4.6.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.6.0","has_docs":true,"inserted_at":"2025-03-20T05:27:42.060718Z"},{"version":"4.5.6","url":"https://hex.pm/api/packages/ash_authentication/releases/4.5.6","has_docs":true,"inserted_at":"2025-03-18T20:31:20.512245Z"},{"version":"4.5.5","url":"https://hex.pm/api/packages/ash_authentication/releases/4.5.5","has_docs":true,"inserted_at":"2025-03-12T13:13:34.028445Z"},{"version":"4.5.4","url":"https://hex.pm/api/packages/ash_authentication/releases/4.5.4","has_docs":true,"inserted_at":"2025-03-12T02:41:48.489064Z"},{"version":"4.5.3","url":"https://hex.pm/api/packages/ash_authentication/releases/4.5.3","has_docs":true,"inserted_at":"2025-03-07T16:52:15.619949Z"},{"version":"4.5.2","url":"https://hex.pm/api/packages/ash_authentication/releases/4.5.2","has_docs":true,"inserted_at":"2025-02-25T20:12:42.473648Z"},{"version":"4.5.1","url":"https://hex.pm/api/packages/ash_authentication/releases/4.5.1","has_docs":true,"inserted_at":"2025-02-14T05:27:16.695762Z"},{"version":"4.5.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.5.0","has_docs":true,"inserted_at":"2025-02-13T22:24:14.800495Z"},{"version":"4.4.9","url":"https://hex.pm/api/packages/ash_authentication/releases/4.4.9","has_docs":true,"inserted_at":"2025-02-11T16:34:34.943303Z"},{"version":"4.4.8","url":"https://hex.pm/api/packages/ash_authentication/releases/4.4.8","has_docs":true,"inserted_at":"2025-02-04T17:38:30.154130Z"},{"version":"4.4.7","url":"https://hex.pm/api/packages/ash_authentication/releases/4.4.7","has_docs":true,"inserted_at":"2025-02-02T11:04:33.527270Z"},{"version":"4.4.6","url":"https://hex.pm/api/packages/ash_authentication/releases/4.4.6","has_docs":true,"inserted_at":"2025-02-01T04:36:06.978503Z"},{"version":"4.4.5","url":"https://hex.pm/api/packages/ash_authentication/releases/4.4.5","has_docs":true,"inserted_at":"2025-01-28T02:11:12.184627Z"},{"version":"4.4.4","url":"https://hex.pm/api/packages/ash_authentication/releases/4.4.4","has_docs":true,"inserted_at":"2025-01-23T19:57:20.422237Z"},{"version":"4.4.3","url":"https://hex.pm/api/packages/ash_authentication/releases/4.4.3","has_docs":true,"inserted_at":"2025-01-23T03:20:31.429230Z"},{"version":"4.4.2","url":"https://hex.pm/api/packages/ash_authentication/releases/4.4.2","has_docs":true,"inserted_at":"2025-01-22T20:14:28.753916Z"},{"version":"4.4.1","url":"https://hex.pm/api/packages/ash_authentication/releases/4.4.1","has_docs":true,"inserted_at":"2025-01-16T05:09:34.224317Z"},{"version":"4.4.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.4.0","has_docs":true,"inserted_at":"2025-01-16T04:02:05.845774Z"},{"version":"4.3.12","url":"https://hex.pm/api/packages/ash_authentication/releases/4.3.12","has_docs":true,"inserted_at":"2025-01-14T22:21:42.581350Z"},{"version":"4.3.11","url":"https://hex.pm/api/packages/ash_authentication/releases/4.3.11","has_docs":true,"inserted_at":"2025-01-13T13:08:57.846708Z"},{"version":"4.3.10","url":"https://hex.pm/api/packages/ash_authentication/releases/4.3.10","has_docs":true,"inserted_at":"2025-01-13T13:27:45.094586Z"},{"version":"4.3.9","url":"https://hex.pm/api/packages/ash_authentication/releases/4.3.9","has_docs":true,"inserted_at":"2024-12-31T19:06:56.305307Z"},{"version":"4.3.8","url":"https://hex.pm/api/packages/ash_authentication/releases/4.3.8","has_docs":true,"inserted_at":"2024-12-31T19:05:31.750364Z"},{"version":"4.3.7","url":"https://hex.pm/api/packages/ash_authentication/releases/4.3.7","has_docs":true,"inserted_at":"2024-12-26T17:28:32.938935Z"},{"version":"4.3.6","url":"https://hex.pm/api/packages/ash_authentication/releases/4.3.6","has_docs":true,"inserted_at":"2024-12-20T16:54:11.838282Z"},{"version":"4.3.5","url":"https://hex.pm/api/packages/ash_authentication/releases/4.3.5","has_docs":true,"inserted_at":"2024-12-12T17:32:33.587974Z"},{"version":"4.3.4","url":"https://hex.pm/api/packages/ash_authentication/releases/4.3.4","has_docs":true,"inserted_at":"2024-12-02T13:52:07.871937Z"},{"version":"4.3.3","url":"https://hex.pm/api/packages/ash_authentication/releases/4.3.3","has_docs":true,"inserted_at":"2024-11-14T20:00:39.119408Z"},{"version":"4.3.2","url":"https://hex.pm/api/packages/ash_authentication/releases/4.3.2","has_docs":true,"inserted_at":"2024-11-13T03:52:34.678755Z"},{"version":"4.3.1","url":"https://hex.pm/api/packages/ash_authentication/releases/4.3.1","has_docs":true,"inserted_at":"2024-11-12T03:07:49.016699Z"},{"version":"4.3.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.3.0","has_docs":true,"inserted_at":"2024-11-05T01:49:14.341032Z"},{"version":"4.2.7","url":"https://hex.pm/api/packages/ash_authentication/releases/4.2.7","has_docs":true,"inserted_at":"2024-11-01T01:35:22.367908Z"},{"version":"4.2.6","url":"https://hex.pm/api/packages/ash_authentication/releases/4.2.6","has_docs":true,"inserted_at":"2024-10-31T13:43:12.232640Z"},{"version":"4.2.5","url":"https://hex.pm/api/packages/ash_authentication/releases/4.2.5","has_docs":true,"inserted_at":"2024-10-23T17:21:17.917725Z"},{"version":"4.2.4","url":"https://hex.pm/api/packages/ash_authentication/releases/4.2.4","has_docs":true,"inserted_at":"2024-10-23T12:04:15.006621Z"},{"version":"4.2.3","url":"https://hex.pm/api/packages/ash_authentication/releases/4.2.3","has_docs":true,"inserted_at":"2024-10-19T04:54:54.960212Z"},{"version":"4.2.2","url":"https://hex.pm/api/packages/ash_authentication/releases/4.2.2","has_docs":true,"inserted_at":"2024-10-15T14:53:01.410848Z"},{"version":"4.2.1","url":"https://hex.pm/api/packages/ash_authentication/releases/4.2.1","has_docs":true,"inserted_at":"2024-10-14T21:35:25.713662Z"},{"version":"4.2.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.2.0","has_docs":true,"inserted_at":"2024-10-07T20:23:23.003156Z"},{"version":"4.1.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.1.0","has_docs":true,"inserted_at":"2024-10-06T16:00:09.942708Z"},{"version":"4.0.4","url":"https://hex.pm/api/packages/ash_authentication/releases/4.0.4","has_docs":true,"inserted_at":"2024-09-01T21:36:10.378015Z"},{"version":"4.0.3","url":"https://hex.pm/api/packages/ash_authentication/releases/4.0.3","has_docs":true,"inserted_at":"2024-08-22T01:03:39.543228Z"},{"version":"4.0.2","url":"https://hex.pm/api/packages/ash_authentication/releases/4.0.2","has_docs":true,"inserted_at":"2024-08-05T03:43:50.574481Z"},{"version":"4.0.1","url":"https://hex.pm/api/packages/ash_authentication/releases/4.0.1","has_docs":true,"inserted_at":"2024-06-11T21:39:44.804298Z"},{"version":"4.0.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.0.0","has_docs":true,"inserted_at":"2024-05-10T22:22:50.308399Z"},{"version":"4.0.0-rc.6","url":"https://hex.pm/api/packages/ash_authentication/releases/4.0.0-rc.6","has_docs":true,"inserted_at":"2024-04-11T21:40:39.686342Z"},{"version":"4.0.0-rc.5","url":"https://hex.pm/api/packages/ash_authentication/releases/4.0.0-rc.5","has_docs":true,"inserted_at":"2024-04-10T00:22:06.610762Z"},{"version":"4.0.0-rc.3","url":"https://hex.pm/api/packages/ash_authentication/releases/4.0.0-rc.3","has_docs":true,"inserted_at":"2024-04-08T22:20:39.822536Z"},{"version":"4.0.0-rc.2","url":"https://hex.pm/api/packages/ash_authentication/releases/4.0.0-rc.2","has_docs":true,"inserted_at":"2024-04-02T16:45:19.066044Z"},{"version":"4.0.0-rc.1","url":"https://hex.pm/api/packages/ash_authentication/releases/4.0.0-rc.1","has_docs":true,"inserted_at":"2024-04-01T20:32:42.312064Z"},{"version":"4.0.0-rc.0","url":"https://hex.pm/api/packages/ash_authentication/releases/4.0.0-rc.0","has_docs":true,"inserted_at":"2024-03-28T02:17:15.281149Z"},{"version":"3.12.4","url":"https://hex.pm/api/packages/ash_authentication/releases/3.12.4","has_docs":true,"inserted_at":"2024-03-11T03:13:46.737742Z"},{"version":"3.12.3","url":"https://hex.pm/api/packages/ash_authentication/releases/3.12.3","has_docs":true,"inserted_at":"2024-02-20T21:06:39.320205Z"},{"version":"3.12.2","url":"https://hex.pm/api/packages/ash_authentication/releases/3.12.2","has_docs":true,"inserted_at":"2024-01-30T21:39:44.000651Z"},{"version":"3.12.1","url":"https://hex.pm/api/packages/ash_authentication/releases/3.12.1","has_docs":true,"inserted_at":"2024-01-25T15:56:13.085792Z"},{"version":"3.12.0","url":"https://hex.pm/api/packages/ash_authentication/releases/3.12.0","has_docs":true,"inserted_at":"2023-11-21T22:14:37.007422Z"},{"version":"3.11.16","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.16","has_docs":true,"inserted_at":"2023-10-25T22:22:00.303082Z"},{"version":"3.11.15","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.15","has_docs":true,"inserted_at":"2023-09-22T11:44:49.622296Z"},{"version":"3.11.14","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.14","has_docs":true,"inserted_at":"2023-09-22T01:56:18.154704Z"},{"version":"3.11.13","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.13","has_docs":true,"inserted_at":"2023-09-22T00:26:22.372279Z"},{"version":"3.11.12","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.12","has_docs":true,"inserted_at":"2023-09-21T21:48:45.007417Z"},{"version":"3.11.11","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.11","has_docs":true,"inserted_at":"2023-09-21T21:22:23.347758Z"},{"version":"3.11.10","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.10","has_docs":true,"inserted_at":"2023-09-18T22:25:10.333895Z"},{"version":"3.11.9","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.9","has_docs":true,"inserted_at":"2023-09-17T23:45:18.561934Z"},{"version":"3.11.8","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.8","has_docs":true,"inserted_at":"2023-08-16T21:26:45.853194Z"},{"version":"3.11.7","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.7","has_docs":true,"inserted_at":"2023-07-14T02:04:30.486834Z"},{"version":"3.11.6","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.6","has_docs":true,"inserted_at":"2023-06-23T03:23:26.820973Z"},{"version":"3.11.5","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.5","has_docs":true,"inserted_at":"2023-06-18T22:46:22.483866Z"},{"version":"3.11.4","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.4","has_docs":true,"inserted_at":"2023-06-15T00:42:19.188857Z"},{"version":"3.11.3","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.3","has_docs":true,"inserted_at":"2023-05-31T22:33:53.197767Z"},{"version":"3.11.2","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.2","has_docs":true,"inserted_at":"2023-05-28T23:08:10.731559Z"},{"version":"3.11.1","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.1","has_docs":true,"inserted_at":"2023-05-04T21:32:09.891248Z"},{"version":"3.11.0","url":"https://hex.pm/api/packages/ash_authentication/releases/3.11.0","has_docs":true,"inserted_at":"2023-05-04T01:28:40.232788Z"},{"version":"3.10.8","url":"https://hex.pm/api/packages/ash_authentication/releases/3.10.8","has_docs":true,"inserted_at":"2023-04-28T19:32:09.495000Z"},{"version":"3.10.7","url":"https://hex.pm/api/packages/ash_authentication/releases/3.10.7","has_docs":true,"inserted_at":"2023-04-28T17:32:52.875163Z"},{"version":"3.10.6","url":"https://hex.pm/api/packages/ash_authentication/releases/3.10.6","has_docs":true,"inserted_at":"2023-04-09T20:34:40.611774Z"},{"version":"3.10.5","url":"https://hex.pm/api/packages/ash_authentication/releases/3.10.5","has_docs":true,"inserted_at":"2023-04-06T03:14:16.134195Z"},{"version":"3.10.4","url":"https://hex.pm/api/packages/ash_authentication/releases/3.10.4","has_docs":true,"inserted_at":"2023-04-03T23:12:59.048862Z"},{"version":"3.10.3","url":"https://hex.pm/api/packages/ash_authentication/releases/3.10.3","has_docs":true,"inserted_at":"2023-04-03T20:56:25.413828Z"},{"version":"3.10.2","url":"https://hex.pm/api/packages/ash_authentication/releases/3.10.2","has_docs":true,"inserted_at":"2023-03-06T21:55:04.748052Z"},{"version":"3.10.1","url":"https://hex.pm/api/packages/ash_authentication/releases/3.10.1","has_docs":true,"inserted_at":"2023-03-06T21:03:41.896460Z"},{"version":"3.10.0","url":"https://hex.pm/api/packages/ash_authentication/releases/3.10.0","has_docs":true,"inserted_at":"2023-03-04T07:04:06.976212Z"},{"version":"3.9.6","url":"https://hex.pm/api/packages/ash_authentication/releases/3.9.6","has_docs":true,"inserted_at":"2023-03-01T23:46:33.342157Z"},{"version":"3.9.5","url":"https://hex.pm/api/packages/ash_authentication/releases/3.9.5","has_docs":true,"inserted_at":"2023-02-23T07:52:03.109861Z"},{"version":"3.9.4","url":"https://hex.pm/api/packages/ash_authentication/releases/3.9.4","has_docs":true,"inserted_at":"2023-02-22T03:47:36.683706Z"},{"version":"3.9.3","url":"https://hex.pm/api/packages/ash_authentication/releases/3.9.3","has_docs":true,"inserted_at":"2023-02-19T21:13:42.851934Z"},{"version":"3.9.2","url":"https://hex.pm/api/packages/ash_authentication/releases/3.9.2","has_docs":true,"inserted_at":"2023-02-12T23:06:32.366812Z"},{"version":"3.9.1","url":"https://hex.pm/api/packages/ash_authentication/releases/3.9.1","has_docs":true,"inserted_at":"2023-02-12T08:41:11.203910Z"},{"version":"3.9.0","url":"https://hex.pm/api/packages/ash_authentication/releases/3.9.0","has_docs":true,"inserted_at":"2023-02-09T18:22:53.625812Z"},{"version":"3.8.0","url":"https://hex.pm/api/packages/ash_authentication/releases/3.8.0","has_docs":true,"inserted_at":"2023-02-09T08:18:43.828055Z"},{"version":"3.7.9","url":"https://hex.pm/api/packages/ash_authentication/releases/3.7.9","has_docs":true,"inserted_at":"2023-02-09T02:48:42.079179Z"},{"version":"3.7.8","url":"https://hex.pm/api/packages/ash_authentication/releases/3.7.8","has_docs":true,"inserted_at":"2023-02-08T03:30:35.518592Z"},{"version":"3.7.6","url":"https://hex.pm/api/packages/ash_authentication/releases/3.7.6","has_docs":true,"inserted_at":"2023-01-30T23:28:36.204443Z"},{"version":"3.7.5","url":"https://hex.pm/api/packages/ash_authentication/releases/3.7.5","has_docs":true,"inserted_at":"2023-01-30T01:54:02.650956Z"},{"version":"3.7.4","url":"https://hex.pm/api/packages/ash_authentication/releases/3.7.4","has_docs":true,"inserted_at":"2023-01-30T00:32:11.120590Z"},{"version":"3.7.3","url":"https://hex.pm/api/packages/ash_authentication/releases/3.7.3","has_docs":true,"inserted_at":"2023-01-18T23:14:57.138377Z"},{"version":"3.7.2","url":"https://hex.pm/api/packages/ash_authentication/releases/3.7.2","has_docs":true,"inserted_at":"2023-01-18T22:46:32.237950Z"},{"version":"3.7.1","url":"https://hex.pm/api/packages/ash_authentication/releases/3.7.1","has_docs":true,"inserted_at":"2023-01-18T07:34:10.601000Z"},{"version":"3.7.0","url":"https://hex.pm/api/packages/ash_authentication/releases/3.7.0","has_docs":true,"inserted_at":"2023-01-18T02:00:15.940968Z"},{"version":"3.6.1","url":"https://hex.pm/api/packages/ash_authentication/releases/3.6.1","has_docs":true,"inserted_at":"2023-01-15T20:08:30.283691Z"},{"version":"3.6.0","url":"https://hex.pm/api/packages/ash_authentication/releases/3.6.0","has_docs":true,"inserted_at":"2023-01-15T19:59:19.741500Z"},{"version":"3.5.3","url":"https://hex.pm/api/packages/ash_authentication/releases/3.5.3","has_docs":true,"inserted_at":"2023-01-13T01:39:10.385502Z"},{"version":"3.5.2","url":"https://hex.pm/api/packages/ash_authentication/releases/3.5.2","has_docs":true,"inserted_at":"2023-01-13T01:38:59.853268Z"},{"version":"3.5.1","url":"https://hex.pm/api/packages/ash_authentication/releases/3.5.1","has_docs":true,"inserted_at":"2023-01-12T05:11:40.443009Z"},{"version":"3.5.0","url":"https://hex.pm/api/packages/ash_authentication/releases/3.5.0","has_docs":true,"inserted_at":"2023-01-12T04:46:42.828793Z"},{"version":"3.3.1","url":"https://hex.pm/api/packages/ash_authentication/releases/3.3.1","has_docs":true,"inserted_at":"2023-01-09T21:52:01.619056Z"},{"version":"3.3.0","url":"https://hex.pm/api/packages/ash_authentication/releases/3.3.0","has_docs":true,"inserted_at":"2023-01-09T21:38:10.988557Z"},{"version":"3.2.2","url":"https://hex.pm/api/packages/ash_authentication/releases/3.2.2","has_docs":true,"inserted_at":"2023-01-09T21:29:19.860658Z"},{"version":"3.2.1","url":"https://hex.pm/api/packages/ash_authentication/releases/3.2.1","has_docs":true,"inserted_at":"2022-12-16T01:52:20.978625Z"},{"version":"3.2.0","url":"https://hex.pm/api/packages/ash_authentication/releases/3.2.0","has_docs":true,"inserted_at":"2022-12-16T00:31:02.150099Z"},{"version":"3.1.0","url":"https://hex.pm/api/packages/ash_authentication/releases/3.1.0","has_docs":true,"inserted_at":"2022-12-14T20:11:09.529921Z"},{"version":"3.0.3","url":"https://hex.pm/api/packages/ash_authentication/releases/3.0.3","has_docs":true,"inserted_at":"2022-12-08T02:37:59.397951Z"}],"html_url":"https://hex.pm/packages/ash_authentication","latest_version":"5.0.0-rc.14","downloads":{"all":946572,"day":2370,"recent":221538,"week":21181},"security_advisories":[{"id":"EEF-CVE-2026-86688","aliases":["CVE-2026-86688","GHSA-v577-944g-7h3x"],"references":[{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/3e1d452cbf1564e87f5f97be882b66fe25af7cfa"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-86688.html"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/a939dde9b917c072cdf10c4b0913a9886a4b0231"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-v577-944g-7h3x"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/872db454405ecad4fcdabd9ff3d8755d1d6a69ae"}],"summary":"Session id is not renewed on authentication in ash_authentication, allowing session fixation","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-86688","published_at":"2026-09-17T21:58:00Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-86688","cvss_score":7.4,"cvss_rating":"high","cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","modified_at":"2026-09-17T22:11:00Z","withdrawn_at":null,"affected":[">= 0.2.0 and < 4.15.0",">= 5.0.0-rc.0 and < 5.0.0-rc.14"]},{"id":"EEF-CVE-2026-76949","aliases":["CVE-2026-76949","GHSA-hh34-374j-pfr5"],"references":[{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-hh34-374j-pfr5"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/9a34136b844abe179da1075067cf2835c64dcc12"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/b9568a53b438247238b1c5a4f49c8d84650f4bba"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/3d3de314692558d06ec13945f857f00514e95a8c"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-76949.html"}],"summary":"Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-76949","published_at":"2026-09-17T21:57:50Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-76949","cvss_score":9.1,"cvss_rating":"critical","cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","modified_at":"2026-09-17T22:10:59Z","withdrawn_at":null,"affected":[">= 4.10.0 and < 4.15.0",">= 5.0.0-rc.0 and < 5.0.0-rc.14"]},{"id":"EEF-CVE-2026-91039","aliases":["CVE-2026-91039","GHSA-73j9-m294-fvv9"],"references":[{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-91039.html"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-73j9-m294-fvv9"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/64530644f9b37ebb76ca14aeb83a77597a0034b7"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/73ad16e452670bbf843550a13361bd41e72ad964"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"}],"summary":"dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-91039","published_at":"2026-09-17T15:19:15Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-91039","cvss_score":9.1,"cvss_rating":"critical","cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","modified_at":"2026-09-17T15:41:03Z","withdrawn_at":null,"affected":[">= 5.0.0-rc.10 and < 5.0.0-rc.14"]},{"id":"EEF-CVE-2026-88952","aliases":["CVE-2026-88952","GHSA-wc6x-276q-jrf9"],"references":[{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/2bd630eef8b7c8ae1e90e8fd43ba12fbc7e256ba"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-wc6x-276q-jrf9"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-88952.html"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/64530644f9b37ebb76ca14aeb83a77597a0034b7"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/42edcd8ebb13fafbb168f12591d7518ce0611fec"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/738bf9f32f2aa0d1bb92ce9ca5c2476cb5710459"}],"summary":"OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-88952","published_at":"2026-09-17T14:15:19Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-88952","cvss_score":9.1,"cvss_rating":"critical","cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","modified_at":"2026-09-17T14:41:02Z","withdrawn_at":null,"affected":[">= 5.0.0-rc.10 and < 5.0.0-rc.14",">= 4.14.0 and < 4.15.0"]},{"id":"EEF-CVE-2026-85500","aliases":["CVE-2026-85500","GHSA-fc47-6pgw-wh22"],"references":[{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-fc47-6pgw-wh22"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/1076639a9d40213088d110c79ba6735b8cc85b16"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/17f4c25a372d1778c9cc457759e6357570d83711"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/7d37bc6e4df6697b5813d2f373f0fdb08f813f98"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-85500.html"}],"summary":"`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-85500","published_at":"2026-09-17T13:09:43Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-85500","cvss_score":9.1,"cvss_rating":"critical","cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","modified_at":"2026-09-17T13:26:03Z","withdrawn_at":null,"affected":[">= 5.0.0-rc.0 and < 5.0.0-rc.14",">= 4.3.8 and < 4.15.0"]},{"id":"EEF-CVE-2026-86533","aliases":["CVE-2026-86533","GHSA-m6x4-4gvp-xwjr"],"references":[{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication_phoenix/commit/0135217e34e621dac79ae3d9559aeee49304b0aa"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication_phoenix"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication_phoenix/security/advisories/GHSA-m6x4-4gvp-xwjr"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-86533.html"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-w374-hvrx-66hg"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/fcaeb73f76f8f2e9aef8bf637690d2a20dd97596"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/a3f49f758f013d2ff086dd9c5ef2d94e921711b4"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/e28e911caa9728d76329afdb0fb26742ffe4eeef"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication_phoenix/commit/a3253fb4fc7145aeb403537af1c24d3a8d51ffb1"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication_phoenix/commit/f7ab005a2aac09707a25521653c94893d328cc52"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"}],"summary":"Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-86533","published_at":"2026-09-17T13:09:37Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-86533","cvss_score":9.1,"cvss_rating":"critical","cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","modified_at":"2026-09-17T14:15:02Z","withdrawn_at":null,"affected":[">= 5.0.0-rc.0 and < 5.0.0-rc.14",">= 4.9.1 and < 4.15.0"]},{"id":"EEF-CVE-2026-81632","aliases":["CVE-2026-81632","GHSA-8jh5-339h-mqx9"],"references":[{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/eca8cadea0f1595ed2c10a0c177b1da9aa9e5269"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication_phoenix"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/8d8ddd25c69b669a92a701af74bff42e1aada998"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/bbf345c1bb7aa28bce5dd856ac0ed2427f103859"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication_phoenix/commit/ff5ad8737748afed9cdfde3ec3a05b8a4702a742"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication_phoenix/commit/920257d0460b9c7cbb42a83d0888c10f4eeeb88a"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication_phoenix/commit/903f3a386e1aba2f7b070187ef6f31215a92bdfd"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-j726-59hm-r46r"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-81632.html"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication_phoenix/security/advisories/GHSA-8jh5-339h-mqx9"}],"summary":"Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-81632","published_at":"2026-09-17T13:09:31Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-81632","cvss_score":7.2,"cvss_rating":"high","cvss_vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","modified_at":"2026-09-17T13:26:04Z","withdrawn_at":null,"affected":[">= 5.0.0-rc.0 and < 5.0.0-rc.14",">= 3.10.5 and < 4.15.0"]},{"id":"EEF-CVE-2026-80218","aliases":["CVE-2026-80218","GHSA-3pr8-f99q-86hp"],"references":[{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/eca8cadea0f1595ed2c10a0c177b1da9aa9e5269"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/2640e1872e1fef4e4606e601bf00102cff784c03"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-3pr8-f99q-86hp"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-80218.html"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/7baac243ca651eee127a84d672eee3fcff42e598"}],"summary":"Sign-in token minted for one resource accepted by another in AshAuthentication","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-80218","published_at":"2026-09-17T13:09:25Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-80218","cvss_score":7.6,"cvss_rating":"high","cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","modified_at":"2026-09-17T13:26:03Z","withdrawn_at":null,"affected":[">= 3.10.5 and < 4.15.0",">= 5.0.0-rc.0 and < 5.0.0-rc.14"]},{"id":"EEF-CVE-2026-78223","aliases":["CVE-2026-78223","GHSA-mfwg-5cpf-px58"],"references":[{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/a939dde9b917c072cdf10c4b0913a9886a4b0231"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/eb86353fe5a547c5ff5fd9af0e2c212518c31c9b"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-78223.html"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-mfwg-5cpf-px58"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/344cebb12faf68e648d3283394073ba0c0f78459"}],"summary":"Token revocation record built from unverified JWT claims in AshAuthentication","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-78223","published_at":"2026-09-17T13:09:19Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-78223","cvss_score":6.9,"cvss_rating":"medium","cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","modified_at":"2026-09-17T13:26:04Z","withdrawn_at":null,"affected":[">= 5.0.0-rc.0 and < 5.0.0-rc.14",">= 0.2.0 and < 4.15.0"]},{"id":"EEF-CVE-2026-86522","aliases":["CVE-2026-86522","GHSA-wg7g-r393-vr3g"],"references":[{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-86522.html"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/57c7cc3236bef0fa9da19cb315414f216488866d"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/fd19358bf0eee53ef13dcf17cc499bd4fb393981"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/3954f277929712755aef57a4a3a821688f121316"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-wg7g-r393-vr3g"}],"summary":"Log injection via an unescaped password reset identity in AshAuthentication","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-86522","published_at":"2026-09-17T13:09:11Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-86522","cvss_score":6.3,"cvss_rating":"medium","cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N","modified_at":"2026-09-17T13:26:03Z","withdrawn_at":null,"affected":[">= 4.2.0 and < 4.15.0",">= 5.0.0-rc.0 and < 5.0.0-rc.14"]},{"id":"EEF-CVE-2026-81637","aliases":["CVE-2026-81637","GHSA-3vcj-gxx8-3p44"],"references":[{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/d7f939cd02bd618bcaa304631846fa75ffc419d7"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-3vcj-gxx8-3p44"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-81637.html"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/c5f589058e04239263f50a1430eb17ea6d5dd1a2"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/bd4352303bc9d72d007f6818775267585a4bcc2f"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"}],"summary":"Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-81637","published_at":"2026-09-17T13:09:06Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-81637","cvss_score":2.3,"cvss_rating":"low","cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","modified_at":"2026-09-17T13:26:03Z","withdrawn_at":null,"affected":[">= 0.6.0 and < 4.15.0",">= 5.0.0-rc.0 and < 5.0.0-rc.14"]},{"id":"EEF-CVE-2026-82761","aliases":["CVE-2026-82761","GHSA-23gr-vcp4-r27q"],"references":[{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-23gr-vcp4-r27q"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/9ef6864b8833d3b795427a7b8dc518a4997d41ab"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/18dfdb36c14aa6a61df8572bce2d5ec36b1d9840"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/cf3d227ef25912cf1b0c5fa80f20001f5c46a102"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-82761.html"}],"summary":"Magic link single-use tokens replayable via TOCTOU race in AshAuthentication","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-82761","published_at":"2026-09-17T13:09:01Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-82761","cvss_score":9.1,"cvss_rating":"critical","cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","modified_at":"2026-09-17T13:26:03Z","withdrawn_at":null,"affected":[">= 5.0.0-rc.0 and < 5.0.0-rc.14",">= 3.9.0 and < 4.15.0"]},{"id":"EEF-CVE-2026-82685","aliases":["CVE-2026-82685","GHSA-g636-26vf-2w63"],"references":[{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-g636-26vf-2w63"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-82685.html"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/1d4bb00617aecae85c33f2ff5bc7e094c6449a6e"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/d7c15c21d39c009206e010cd67e2d86370fe7a28"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/2a2396af131ab67e2f445b805fecce8e6ca86c0e"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"}],"summary":"Confirmation token accepted on any record in AshAuthentication","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-82685","published_at":"2026-09-17T13:08:56Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-82685","cvss_score":7.6,"cvss_rating":"high","cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","modified_at":"2026-09-17T13:26:04Z","withdrawn_at":null,"affected":[">= 5.0.0-rc.0 and < 5.0.0-rc.14",">= 0.5.0 and < 4.15.0"]},{"id":"EEF-CVE-2026-82760","aliases":["CVE-2026-82760","GHSA-q876-xr24-2mcx"],"references":[{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-q876-xr24-2mcx"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-82760.html"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/f3a53f480088419788d5c3934af3131fa9066773"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/d5a5d4cb5cc17fbd6e2a120a6111b47accad4b8e"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/dfb19c897853686ab481c5e773f7a1a0c74dea04"}],"summary":"Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-82760","published_at":"2026-09-17T13:08:46Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-82760","cvss_score":8.2,"cvss_rating":"high","cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","modified_at":"2026-09-17T13:26:04Z","withdrawn_at":null,"affected":[">= 4.8.0 and < 4.15.0",">= 5.0.0-rc.0 and < 5.0.0-rc.14"]},{"id":"EEF-CVE-2026-82759","aliases":["CVE-2026-82759","GHSA-cgqj-pcpq-xhfm"],"references":[{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/255cfc9c0e511b7e0de39f8b3d676ae994fae06c"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-82759.html"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-cgqj-pcpq-xhfm"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/d8a9c4b6bde828fdc8346198d5e4f588b5937541"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/c3a6d5fe0d4fd383ea81b0402db0a96638479478"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"}],"summary":"Reversible IP address pseudonymisation in AshAuthentication audit log hash mode","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-82759","published_at":"2026-09-17T13:08:21Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-82759","cvss_score":1.8,"cvss_rating":"low","cvss_vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","modified_at":"2026-09-17T13:26:04Z","withdrawn_at":null,"affected":[">= 5.0.0-rc.0 and < 5.0.0-rc.14",">= 4.12.0 and < 4.15.0"]},{"id":"EEF-CVE-2026-82723","aliases":["CVE-2026-82723","GHSA-59wx-q3r8-ghv4"],"references":[{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/f6b49cc98b9ff7c16a1aeb12e35633a8d93a211f"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/17ea0dff3bad56a7e915e050c43ab7160b37901f"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/255cfc9c0e511b7e0de39f8b3d676ae994fae06c"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-82723.html"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-59wx-q3r8-ghv4"}],"summary":"Actor record with password digest stored in AshAuthentication audit log entries","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-82723","published_at":"2026-09-17T13:08:05Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-82723","cvss_score":1.8,"cvss_rating":"low","cvss_vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","modified_at":"2026-09-24T21:01:08Z","withdrawn_at":null,"affected":[">= 5.0.0-rc.0 and < 5.0.0-rc.2",">= 4.12.0 and < 4.15.0"]},{"id":"GHSA-777c-2fxx-qr28","aliases":["CVE-2026-49757","EEF-CVE-2026-49757"],"references":[{"type":"WEB","url":"https://osv.dev/vulnerability/EEF-CVE-2026-49757"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-49757.html"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/728b8d28c1b5f465fa1116ef044a815300fc733d"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/64530644f9b37ebb76ca14aeb83a77597a0034b7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49757"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-777c-2fxx-qr28"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/releases/tag/v5.0.0-rc.10"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/releases/tag/v4.14.0"},{"type":"PACKAGE","url":"https://github.com/team-alembic/ash_authentication"}],"summary":"AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching","api_url":"https://api.osv.dev/v1/vulns/GHSA-777c-2fxx-qr28","published_at":"2026-08-25T18:20:27Z","html_url":"https://osv.dev/vulnerability/GHSA-777c-2fxx-qr28","cvss_score":9.2,"cvss_rating":"critical","cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","modified_at":"2026-08-26T01:21:17Z","withdrawn_at":null,"affected":[">= 5.0.0-rc.0 and < 5.0.0-rc.10",">= 0.1.0 and < 4.14.0"]},{"id":"EEF-CVE-2026-65633","aliases":["CVE-2026-65633","GHSA-6vcj-3h59-rrc3"],"references":[{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-6vcj-3h59-rrc3"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/124eddd1bbeb40289c3fe8831ac10677a19fcf09"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/8cf8b2d4426172be0900a3505e9491800b951750"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-65633.html"}],"summary":"Purpose-limited JWT accepted as full bearer authentication in AshAuthentication","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-65633","published_at":"2026-08-25T08:03:51Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-65633","cvss_score":7.6,"cvss_rating":"high","cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","modified_at":"2026-09-08T04:15:03Z","withdrawn_at":null,"affected":[">= 3.10.5 and < 4.14.2",">= 5.0.0-rc.0 and < 5.0.0-rc.13"]},{"id":"EEF-CVE-2026-66882","aliases":["CVE-2026-66882","GHSA-54fc-x3hv-ffhw"],"references":[{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/62719710790a150a9eacab9c0a066e0d122d15be"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-66882.html"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-54fc-x3hv-ffhw"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/0bd5199db066be22b2ca1ec8bc6109e5d62e6070"}],"summary":"Reflected XSS in AshAuthentication confirmation and magic link interaction forms","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-66882","published_at":"2026-08-25T08:03:47Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-66882","cvss_score":2.1,"cvss_rating":"low","cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","modified_at":"2026-09-08T04:15:03Z","withdrawn_at":null,"affected":[">= 4.8.0 and < 4.14.2",">= 5.0.0-rc.0 and < 5.0.0-rc.13"]},{"id":"EEF-CVE-2026-49757","aliases":["CVE-2026-49757","GHSA-777c-2fxx-qr28"],"references":[{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/64530644f9b37ebb76ca14aeb83a77597a0034b7"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/728b8d28c1b5f465fa1116ef044a815300fc733d"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-49757.html"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-777c-2fxx-qr28"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"}],"summary":"OAuth2/OIDC account takeover in AshAuthentication via email-based user matching","api_url":"https://api.osv.dev/v1/vulns/EEF-CVE-2026-49757","published_at":"2026-06-15T10:07:17Z","html_url":"https://osv.dev/vulnerability/EEF-CVE-2026-49757","cvss_score":9.2,"cvss_rating":"critical","cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","modified_at":"2026-07-30T18:22:06Z","withdrawn_at":null,"affected":[">= 0.1.0 and < 4.14.0",">= 5.0.0-rc.0 and < 5.0.0-rc.10"]},{"id":"GHSA-3988-q8q7-p787","aliases":["CVE-2025-32782"],"references":[{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-3988-q8q7-p787"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32782"},{"type":"PACKAGE","url":"https://github.com/team-alembic/ash_authentication"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/99ea38977fd4f421d2aaae0c2fb29f8e5f8f707d"}],"summary":"ash_authentication has email link auto-click account confirmation vulnerability","api_url":"https://api.osv.dev/v1/vulns/GHSA-3988-q8q7-p787","published_at":"2025-04-14T23:00:39Z","html_url":"https://osv.dev/vulnerability/GHSA-3988-q8q7-p787","cvss_score":5.3,"cvss_rating":"medium","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","modified_at":"2025-12-10T00:41:50Z","withdrawn_at":null,"affected":["< 4.7.0"]},{"id":"GHSA-qrm9-f75w-hg4c","aliases":["CVE-2025-25202"],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-25202"},{"type":"PACKAGE","url":"https://github.com/team-alembic/ash_authentication"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/2dee55252df26fe3d990ff1199397cdcf1bfea8a"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-qrm9-f75w-hg4c"}],"summary":"Ash Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install`","api_url":"https://api.osv.dev/v1/vulns/GHSA-qrm9-f75w-hg4c","published_at":"2025-02-11T18:12:33Z","html_url":"https://osv.dev/vulnerability/GHSA-qrm9-f75w-hg4c","cvss_score":6.3,"cvss_rating":"medium","cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","modified_at":"2025-12-10T00:30:10Z","withdrawn_at":null,"affected":[">= 4.1.0 and < 4.4.9"]}],"docs_html_url":"https://ash-authentication.hexdocs.pm/","configs":{"erlang.mk":"dep_ash_authentication = hex 4.15.0","mix.exs":"{:ash_authentication, \"~> 4.15\"}","rebar.config":"{ash_authentication, \"4.15.0\"}"},"retirements":{"4.13.1":{"message":"This break Google auth flows due to an assent upgrade, will be fixed in next release","reason":"other"},"4.13.2":{"message":"incorrectly pinned assent version","reason":"other"}},"latest_stable_version":"4.15.0"}