An OAuth 2.1 authorization server for Ash Framework apps — RFC 7591 dynamic client registration, PKCE, audience-bound JWTs, refresh-token rotation, and a built-in consent flow on top of ash_authentication + Phoenix.
Current section
6 Advisories
Jump to
Current section
6 Advisories
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-82758.html
- https://github.com/ash-project/ash_authentication_oauth2_server/commit/30a87101871775d27d79f9ad6f29eafa4779e118
- https://github.com/ash-project/ash_authentication_oauth2_server/security/advisories/GHSA-fxc6-vp68-87pw
- https://hex.pm/packages/ash_authentication_oauth2_server
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-82757.html
- https://github.com/ash-project/ash_authentication_oauth2_server/commit/268b591261a3473ab9b87272963e4dd2fd99d972
- https://github.com/ash-project/ash_authentication_oauth2_server/security/advisories/GHSA-wprp-8gvj-p6cv
- https://hex.pm/packages/ash_authentication_oauth2_server
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-82756.html
- https://github.com/ash-project/ash_authentication_oauth2_server/commit/09f97476715da031b136eaec7b2cda2363ad8149
- https://github.com/ash-project/ash_authentication_oauth2_server/security/advisories/GHSA-2h3v-83jg-2qmm
- https://hex.pm/packages/ash_authentication_oauth2_server
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-82755.html
- https://github.com/ash-project/ash_authentication_oauth2_server/commit/768d87f70e4e97ae1d2bf1606b5bf3f4d03f24a1
- https://github.com/ash-project/ash_authentication_oauth2_server/security/advisories/GHSA-crqf-7m54-4hgc
- https://hex.pm/packages/ash_authentication_oauth2_server
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-82754.html
- https://github.com/ash-project/ash_authentication_oauth2_server/commit/a72972d7ed3eb74c05dfa0653a258ef14454459a
- https://github.com/ash-project/ash_authentication_oauth2_server/security/advisories/GHSA-wwxg-h779-3wf4
- https://hex.pm/packages/ash_authentication_oauth2_server
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-82753.html
- https://github.com/ash-project/ash_authentication_oauth2_server/commit/45e24f69e0f95d67413e2508acc2264156acb5ac
- https://github.com/ash-project/ash_authentication_oauth2_server/security/advisories/GHSA-9pv3-wxjm-f846
- https://hex.pm/packages/ash_authentication_oauth2_server
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
65
yesterday
226
last 7 days
1 276
all time
21 149