ash_authentication
4.15.0
Authentication extension for the Ash Framework.
Current section
21 Advisories
Jump to
Current section
21 Advisories
Session id is not renewed on authentication in ash_authentication, allowing session fixation
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-86688.html
- https://github.com/team-alembic/ash_authentication/commit/3e1d452cbf1564e87f5f97be882b66fe25af7cfa
- https://github.com/team-alembic/ash_authentication/commit/872db454405ecad4fcdabd9ff3d8755d1d6a69ae
- https://github.com/team-alembic/ash_authentication/commit/a939dde9b917c072cdf10c4b0913a9886a4b0231
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-v577-944g-7h3x
- https://hex.pm/packages/ash_authentication
Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-76949.html
- https://github.com/team-alembic/ash_authentication/commit/3d3de314692558d06ec13945f857f00514e95a8c
- https://github.com/team-alembic/ash_authentication/commit/9a34136b844abe179da1075067cf2835c64dcc12
- https://github.com/team-alembic/ash_authentication/commit/b9568a53b438247238b1c5a4f49c8d84650f4bba
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-hh34-374j-pfr5
- https://hex.pm/packages/ash_authentication
dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-91039.html
- https://github.com/team-alembic/ash_authentication/commit/64530644f9b37ebb76ca14aeb83a77597a0034b7
- https://github.com/team-alembic/ash_authentication/commit/73ad16e452670bbf843550a13361bd41e72ad964
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-73j9-m294-fvv9
- https://hex.pm/packages/ash_authentication
OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-88952.html
- https://github.com/team-alembic/ash_authentication/commit/2bd630eef8b7c8ae1e90e8fd43ba12fbc7e256ba
- https://github.com/team-alembic/ash_authentication/commit/42edcd8ebb13fafbb168f12591d7518ce0611fec
- https://github.com/team-alembic/ash_authentication/commit/64530644f9b37ebb76ca14aeb83a77597a0034b7
- https://github.com/team-alembic/ash_authentication/commit/738bf9f32f2aa0d1bb92ce9ca5c2476cb5710459
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-wc6x-276q-jrf9
- https://hex.pm/packages/ash_authentication
`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-85500.html
- https://github.com/team-alembic/ash_authentication/commit/1076639a9d40213088d110c79ba6735b8cc85b16
- https://github.com/team-alembic/ash_authentication/commit/17f4c25a372d1778c9cc457759e6357570d83711
- https://github.com/team-alembic/ash_authentication/commit/7d37bc6e4df6697b5813d2f373f0fdb08f813f98
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-fc47-6pgw-wh22
- https://hex.pm/packages/ash_authentication
Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-86533.html
- https://github.com/team-alembic/ash_authentication/commit/a3f49f758f013d2ff086dd9c5ef2d94e921711b4
- https://github.com/team-alembic/ash_authentication/commit/e28e911caa9728d76329afdb0fb26742ffe4eeef
- https://github.com/team-alembic/ash_authentication/commit/fcaeb73f76f8f2e9aef8bf637690d2a20dd97596
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-w374-hvrx-66hg
- https://github.com/team-alembic/ash_authentication_phoenix/commit/0135217e34e621dac79ae3d9559aeee49304b0aa
- https://github.com/team-alembic/ash_authentication_phoenix/commit/a3253fb4fc7145aeb403537af1c24d3a8d51ffb1
- https://github.com/team-alembic/ash_authentication_phoenix/commit/f7ab005a2aac09707a25521653c94893d328cc52
- https://github.com/team-alembic/ash_authentication_phoenix/security/advisories/GHSA-m6x4-4gvp-xwjr
- https://hex.pm/packages/ash_authentication
- https://hex.pm/packages/ash_authentication_phoenix
Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-81632.html
- https://github.com/team-alembic/ash_authentication/commit/8d8ddd25c69b669a92a701af74bff42e1aada998
- https://github.com/team-alembic/ash_authentication/commit/bbf345c1bb7aa28bce5dd856ac0ed2427f103859
- https://github.com/team-alembic/ash_authentication/commit/eca8cadea0f1595ed2c10a0c177b1da9aa9e5269
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-j726-59hm-r46r
- https://github.com/team-alembic/ash_authentication_phoenix/commit/903f3a386e1aba2f7b070187ef6f31215a92bdfd
- https://github.com/team-alembic/ash_authentication_phoenix/commit/920257d0460b9c7cbb42a83d0888c10f4eeeb88a
- https://github.com/team-alembic/ash_authentication_phoenix/commit/ff5ad8737748afed9cdfde3ec3a05b8a4702a742
- https://github.com/team-alembic/ash_authentication_phoenix/security/advisories/GHSA-8jh5-339h-mqx9
- https://hex.pm/packages/ash_authentication
- https://hex.pm/packages/ash_authentication_phoenix
Sign-in token minted for one resource accepted by another in AshAuthentication
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-80218.html
- https://github.com/team-alembic/ash_authentication/commit/2640e1872e1fef4e4606e601bf00102cff784c03
- https://github.com/team-alembic/ash_authentication/commit/7baac243ca651eee127a84d672eee3fcff42e598
- https://github.com/team-alembic/ash_authentication/commit/eca8cadea0f1595ed2c10a0c177b1da9aa9e5269
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-3pr8-f99q-86hp
- https://hex.pm/packages/ash_authentication
Token revocation record built from unverified JWT claims in AshAuthentication
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-78223.html
- https://github.com/team-alembic/ash_authentication/commit/344cebb12faf68e648d3283394073ba0c0f78459
- https://github.com/team-alembic/ash_authentication/commit/a939dde9b917c072cdf10c4b0913a9886a4b0231
- https://github.com/team-alembic/ash_authentication/commit/eb86353fe5a547c5ff5fd9af0e2c212518c31c9b
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-mfwg-5cpf-px58
- https://hex.pm/packages/ash_authentication
Log injection via an unescaped password reset identity in AshAuthentication
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-86522.html
- https://github.com/team-alembic/ash_authentication/commit/3954f277929712755aef57a4a3a821688f121316
- https://github.com/team-alembic/ash_authentication/commit/57c7cc3236bef0fa9da19cb315414f216488866d
- https://github.com/team-alembic/ash_authentication/commit/fd19358bf0eee53ef13dcf17cc499bd4fb393981
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-wg7g-r393-vr3g
- https://hex.pm/packages/ash_authentication
Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-81637.html
- https://github.com/team-alembic/ash_authentication/commit/bd4352303bc9d72d007f6818775267585a4bcc2f
- https://github.com/team-alembic/ash_authentication/commit/c5f589058e04239263f50a1430eb17ea6d5dd1a2
- https://github.com/team-alembic/ash_authentication/commit/d7f939cd02bd618bcaa304631846fa75ffc419d7
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-3vcj-gxx8-3p44
- https://hex.pm/packages/ash_authentication
Magic link single-use tokens replayable via TOCTOU race in AshAuthentication
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-82761.html
- https://github.com/team-alembic/ash_authentication/commit/18dfdb36c14aa6a61df8572bce2d5ec36b1d9840
- https://github.com/team-alembic/ash_authentication/commit/9ef6864b8833d3b795427a7b8dc518a4997d41ab
- https://github.com/team-alembic/ash_authentication/commit/cf3d227ef25912cf1b0c5fa80f20001f5c46a102
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-23gr-vcp4-r27q
- https://hex.pm/packages/ash_authentication
Confirmation token accepted on any record in AshAuthentication
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-82685.html
- https://github.com/team-alembic/ash_authentication/commit/1d4bb00617aecae85c33f2ff5bc7e094c6449a6e
- https://github.com/team-alembic/ash_authentication/commit/2a2396af131ab67e2f445b805fecce8e6ca86c0e
- https://github.com/team-alembic/ash_authentication/commit/d7c15c21d39c009206e010cd67e2d86370fe7a28
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-g636-26vf-2w63
- https://hex.pm/packages/ash_authentication
Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-82760.html
- https://github.com/team-alembic/ash_authentication/commit/d5a5d4cb5cc17fbd6e2a120a6111b47accad4b8e
- https://github.com/team-alembic/ash_authentication/commit/dfb19c897853686ab481c5e773f7a1a0c74dea04
- https://github.com/team-alembic/ash_authentication/commit/f3a53f480088419788d5c3934af3131fa9066773
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-q876-xr24-2mcx
- https://hex.pm/packages/ash_authentication
Reversible IP address pseudonymisation in AshAuthentication audit log hash mode
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-82759.html
- https://github.com/team-alembic/ash_authentication/commit/255cfc9c0e511b7e0de39f8b3d676ae994fae06c
- https://github.com/team-alembic/ash_authentication/commit/c3a6d5fe0d4fd383ea81b0402db0a96638479478
- https://github.com/team-alembic/ash_authentication/commit/d8a9c4b6bde828fdc8346198d5e4f588b5937541
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-cgqj-pcpq-xhfm
- https://hex.pm/packages/ash_authentication
Actor record with password digest stored in AshAuthentication audit log entries
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-82723.html
- https://github.com/team-alembic/ash_authentication/commit/17ea0dff3bad56a7e915e050c43ab7160b37901f
- https://github.com/team-alembic/ash_authentication/commit/255cfc9c0e511b7e0de39f8b3d676ae994fae06c
- https://github.com/team-alembic/ash_authentication/commit/f6b49cc98b9ff7c16a1aeb12e35633a8d93a211f
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-59wx-q3r8-ghv4
- https://hex.pm/packages/ash_authentication
OAuth2/OIDC account takeover in AshAuthentication via email-based user matching
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-49757.html
- https://github.com/team-alembic/ash_authentication
- https://github.com/team-alembic/ash_authentication/commit/64530644f9b37ebb76ca14aeb83a77597a0034b7
- https://github.com/team-alembic/ash_authentication/commit/728b8d28c1b5f465fa1116ef044a815300fc733d
- https://github.com/team-alembic/ash_authentication/releases/tag/v4.14.0
- https://github.com/team-alembic/ash_authentication/releases/tag/v5.0.0-rc.10
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-777c-2fxx-qr28
- https://hex.pm/packages/ash_authentication
- https://nvd.nist.gov/vuln/detail/CVE-2026-49757
- https://osv.dev/vulnerability/EEF-CVE-2026-49757
Purpose-limited JWT accepted as full bearer authentication in AshAuthentication
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-65633.html
- https://github.com/team-alembic/ash_authentication/commit/124eddd1bbeb40289c3fe8831ac10677a19fcf09
- https://github.com/team-alembic/ash_authentication/commit/8cf8b2d4426172be0900a3505e9491800b951750
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-6vcj-3h59-rrc3
- https://hex.pm/packages/ash_authentication
Reflected XSS in AshAuthentication confirmation and magic link interaction forms
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-66882.html
- https://github.com/team-alembic/ash_authentication/commit/0bd5199db066be22b2ca1ec8bc6109e5d62e6070
- https://github.com/team-alembic/ash_authentication/commit/62719710790a150a9eacab9c0a066e0d122d15be
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-54fc-x3hv-ffhw
- https://hex.pm/packages/ash_authentication
ash_authentication has email link auto-click account confirmation vulnerability
Affected Versions
Ash Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install`
Affected Versions
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
21 810
yesterday
2 370
last 7 days
21 181
all time
946 572