Packages

An OAuth 2.1 authorization server for Ash Framework apps — RFC 7591 dynamic client registration, PKCE, audience-bound JWTs, refresh-token rotation, and a built-in consent flow on top of ash_authentication + Phoenix.

Current section

6 Advisories

Jump to
EEF-CVE-2026-82758 CVE-2026-82758 GHSA-fxc6-vp68-87pw

ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint

September 07, 2026
EEF-CVE-2026-82757 CVE-2026-82757 GHSA-wprp-8gvj-p6cv

ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF

September 07, 2026
EEF-CVE-2026-82756 CVE-2026-82756 GHSA-2h3v-83jg-2qmm

ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection

September 07, 2026
EEF-CVE-2026-82755 CVE-2026-82755 GHSA-crqf-7m54-4hgc

ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion

September 07, 2026
EEF-CVE-2026-82754 CVE-2026-82754 GHSA-wwxg-h779-3wf4

ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls

September 07, 2026
EEF-CVE-2026-82753 CVE-2026-82753 GHSA-9pv3-wxjm-f846

Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server

September 07, 2026

Checksum

Dependency Config

mix.exs

rebar.config

Gleam

erlang.mk

Package Details

Downloads Last 30 days, all versions
0 100 200 300 400

this version

65

yesterday

226

last 7 days

1 276

all time

21 149

Last Updated

Sep 07, 2026

License

MIT

Build Tools

mix

Publisher

ash-project ash-project