ash_authentication
4.14.2
Authentication extension for the Ash Framework.
Current section
5 Advisories
Jump to
Current section
5 Advisories
OAuth2/OIDC account takeover in AshAuthentication via email-based user matching
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-49757.html
- https://github.com/team-alembic/ash_authentication
- https://github.com/team-alembic/ash_authentication/commit/64530644f9b37ebb76ca14aeb83a77597a0034b7
- https://github.com/team-alembic/ash_authentication/commit/728b8d28c1b5f465fa1116ef044a815300fc733d
- https://github.com/team-alembic/ash_authentication/releases/tag/v4.14.0
- https://github.com/team-alembic/ash_authentication/releases/tag/v5.0.0-rc.10
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-777c-2fxx-qr28
- https://hex.pm/packages/ash_authentication
- https://nvd.nist.gov/vuln/detail/CVE-2026-49757
- https://osv.dev/vulnerability/EEF-CVE-2026-49757
Purpose-limited JWT accepted as full bearer authentication in AshAuthentication
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-65633.html
- https://github.com/team-alembic/ash_authentication/commit/124eddd1bbeb40289c3fe8831ac10677a19fcf09
- https://github.com/team-alembic/ash_authentication/commit/8cf8b2d4426172be0900a3505e9491800b951750
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-6vcj-3h59-rrc3
- https://hex.pm/packages/ash_authentication
Reflected XSS in AshAuthentication confirmation and magic link interaction forms
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-66882.html
- https://github.com/team-alembic/ash_authentication/commit/0bd5199db066be22b2ca1ec8bc6109e5d62e6070
- https://github.com/team-alembic/ash_authentication/commit/62719710790a150a9eacab9c0a066e0d122d15be
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-54fc-x3hv-ffhw
- https://hex.pm/packages/ash_authentication
ash_authentication has email link auto-click account confirmation vulnerability
Affected Versions
Ash Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install`
Affected Versions
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
20 504
yesterday
2 910
last 7 days
17 826
all time
882 184