Current section

21 Advisories

Jump to
EEF-CVE-2026-86688 CVE-2026-86688 GHSA-v577-944g-7h3x

Session id is not renewed on authentication in ash_authentication, allowing session fixation

September 17, 2026
EEF-CVE-2026-76949 CVE-2026-76949 GHSA-hh34-374j-pfr5

Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement

September 17, 2026
EEF-CVE-2026-91039 CVE-2026-91039 GHSA-73j9-m294-fvv9

dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover

September 17, 2026
EEF-CVE-2026-85500 CVE-2026-85500 GHSA-fc47-6pgw-wh22

`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication

September 17, 2026
EEF-CVE-2026-80218 CVE-2026-80218 GHSA-3pr8-f99q-86hp

Sign-in token minted for one resource accepted by another in AshAuthentication

September 17, 2026
EEF-CVE-2026-78223 CVE-2026-78223 GHSA-mfwg-5cpf-px58

Token revocation record built from unverified JWT claims in AshAuthentication

September 17, 2026
EEF-CVE-2026-81637 CVE-2026-81637 GHSA-3vcj-gxx8-3p44

Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication

September 17, 2026
EEF-CVE-2026-82761 CVE-2026-82761 GHSA-23gr-vcp4-r27q

Magic link single-use tokens replayable via TOCTOU race in AshAuthentication

September 17, 2026
EEF-CVE-2026-82760 CVE-2026-82760 GHSA-q876-xr24-2mcx

Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in

September 17, 2026
EEF-CVE-2026-82759 CVE-2026-82759 GHSA-cgqj-pcpq-xhfm

Reversible IP address pseudonymisation in AshAuthentication audit log hash mode

September 17, 2026
EEF-CVE-2026-82723 CVE-2026-82723 GHSA-59wx-q3r8-ghv4

Actor record with password digest stored in AshAuthentication audit log entries

September 17, 2026
EEF-CVE-2026-65633 CVE-2026-65633 GHSA-6vcj-3h59-rrc3

Purpose-limited JWT accepted as full bearer authentication in AshAuthentication

August 25, 2026
EEF-CVE-2026-66882 CVE-2026-66882 GHSA-54fc-x3hv-ffhw

Reflected XSS in AshAuthentication confirmation and magic link interaction forms

August 25, 2026
GHSA-3988-q8q7-p787 CVE-2025-32782

ash_authentication has email link auto-click account confirmation vulnerability

April 14, 2025
GHSA-qrm9-f75w-hg4c CVE-2025-25202

Ash Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install`

February 11, 2025

Checksum

Dependency Config

mix.exs

rebar.config

Gleam

erlang.mk

Package Details

Downloads Last 30 days, all versions
0 1K 2K 3K 4K

this version

21 810

yesterday

2 370

last 7 days

21 181

all time

946 572

Last Updated

Sep 17, 2026

License

MIT

Build Tools

mix

Publisher

jamesotron jamesotron