ash_authentication
4.14.1
Authentication extension for the Ash Framework.
Current section
3 Advisories
Jump to
Current section
3 Advisories
OAuth2/OIDC account takeover in AshAuthentication via email-based user matching
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-49757.html
- https://github.com/team-alembic/ash_authentication/commit/64530644f9b37ebb76ca14aeb83a77597a0034b7
- https://github.com/team-alembic/ash_authentication/commit/728b8d28c1b5f465fa1116ef044a815300fc733d
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-777c-2fxx-qr28
- https://hex.pm/packages/ash_authentication
ash_authentication has email link auto-click account confirmation vulnerability
Affected Versions
Ash Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install`
Affected Versions
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
1 933
yesterday
2 173
last 7 days
14 855
all time
689 033