ash_authentication
Hex21 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ash_authenticationpage 1 of 1
- CVE-2025-25202MEDIUMCVSS 6.5EG 6.5fixed in 4.4.92025-02-11
vulnerable: 4.1.0 ... 4.4.8 (31 versions)
Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present since AshAuthentication v4.1.0 and who have used the magic link strategy _or_ are manuall…
- CVE-2025-32782MEDIUMCVSS 5.3EG 5.3fixed in 4.7.02025-04-15
vulnerable: 3.0.3 ... 4.6.4 (116 versions)
Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently uses a GET request triggered by clicking a link sent via email. Some email clients and security tools (e.g., Outlook, vi…
- CVE-2026-49757CRITICALCVSS 9.2EG 9.2fixed in 4.14.0 or 5.0.0-rc.10, by version range2026-06-15
vulnerable: 5.0.0-rc.0 ... 5.0.0-rc.9 (10 versions)
Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via OAuth2/OIDC sign-in. AshAuthentication's OAuth2 and OIDC family strategies matched the local user by email addres…
- CVE-2026-65633HIGHCVSS 7.6EG 7.6fixed in 4.14.2 or 5.0.0-rc.13, by version range2026-08-25
vulnerable: 3.10.5 ... 5.0.0-rc.9 (131 versions)
Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification. The bearer-token authentication he…
- CVE-2026-66882LOWCVSS 2.1EG 2.1fixed in 4.14.2 or 5.0.0-rc.13, by version range2026-08-25
vulnerable: 4.10.0 ... 5.0.0-rc.9 (43 versions)
Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows reflected cross-site scripting via the confirmation and magic link interaction forms. When a strategy is configured w…
- CVE-2026-76949CRITICALCVSS 9.1EG 9.1fixed in 4.15.0 or 5.0.0-rc.14, by version range2026-09-17
vulnerable: 4.10.0 ... 5.0.0-rc.9 (28 versions)
Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for the attacker's own a…
- CVE-2026-78223MEDIUMCVSS 6.9EG 6.9fixed in 4.15.0 or 5.0.0-rc.14, by version range2026-09-17
vulnerable: 3.0.3 ... 5.0.0-rc.9 (168 versions)
Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource. AshAuthentication.…
- CVE-2026-80218HIGHCVSS 7.6EG 7.6fixed in 4.15.0 or 5.0.0-rc.14, by version range2026-09-17
vulnerable: 3.10.5 ... 5.0.0-rc.9 (133 versions)
Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource. AshAuthentication.Strategy.Password.SignI…
- CVE-2026-81632HIGHCVSS 7.2EG 7.2fixed in 4.15.0 or 5.0.0-rc.14, by version range2026-09-17
vulnerable: 3.10.5 ... 5.0.0-rc.9 (133 versions)
Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its own…
- CVE-2026-81637LOWCVSS 2.3EG 2.3fixed in 4.15.0 or 5.0.0-rc.14, by version range2026-09-17
vulnerable: 3.0.3 ... 5.0.0-rc.9 (168 versions)
Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attacker-controlled account. AshAuthenticatio…
- CVE-2026-82685HIGHCVSS 7.6EG 7.6fixed in 4.15.0 or 5.0.0-rc.14, by version range2026-09-17
vulnerable: 3.0.3 ... 5.0.0-rc.9 (168 versions)
Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over that account. A confirmation token is…
- CVE-2026-82723LOWCVSS 1.8EG 1.8fixed in 4.15.0 or 5.0.0-rc.2, by version range2026-09-17
vulnerable: 4.12.0 ... 5.0.0-rc.1 (14 versions)
Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The `audit_log` add-on builds each entry's `extra_data` in `AshAuth…
- CVE-2026-82759LOWCVSS 1.8EG 1.8fixed in 4.15.0 or 5.0.0-rc.14, by version range2026-09-17
vulnerable: 4.12.0 ... 5.0.0-rc.9 (26 versions)
Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover the client IP addresses that the audit log add-on's :hash privacy mode is meant to pseudonymise. As…
- CVE-2026-82760HIGHCVSS 8.2EG 8.2fixed in 4.15.0 or 5.0.0-rc.14, by version range2026-09-17
vulnerable: 4.10.0 ... 5.0.0-rc.9 (45 versions)
Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an oversized base62 segment in a submitted API key. AshAuthentication.Base.decode62/1 in l…
- CVE-2026-82761CRITICALCVSS 9.1EG 9.1fixed in 4.15.0 or 5.0.0-rc.14, by version range2026-09-17
vulnerable: 3.10.0 ... 5.0.0-rc.9 (145 versions)
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as the target subject. A magic link configured…
- CVE-2026-85500CRITICALCVSS 9.1EG 9.1fixed in 4.15.0 or 5.0.0-rc.14, by version range2026-09-17
vulnerable: 4.10.0 ... 5.0.0-rc.9 (79 versions)
Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.ch…
- CVE-2026-86522MEDIUMCVSS 6.3EG 6.3fixed in 4.15.0 or 5.0.0-rc.14, by version range2026-09-17
vulnerable: 4.10.0 ... 5.0.0-rc.9 (95 versions)
Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or control characters. …
- CVE-2026-86533CRITICALCVSS 9.1EG 9.1fixed in 4.15.0 or 5.0.0-rc.14, by version range2026-09-17
vulnerable: 4.10.0 ... 5.0.0-rc.9 (37 versions)
Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_pre…
- CVE-2026-86688HIGHCVSS 7.4EG 7.4fixed in 4.15.0 or 5.0.0-rc.14, by version range2026-09-17
vulnerable: 3.0.3 ... 5.0.0-rc.9 (168 versions)
Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs in. AshAuthentication.Plug.Helpers.store…
- CVE-2026-88952CRITICALCVSS 9.1EG 9.1fixed in 4.15.0 or 5.0.0-rc.14, by version range2026-09-17
vulnerable: 4.14.0 ... 5.0.0-rc.13 (7 versions)
Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an OAuth2 identity to an account that is not theirs. AshAuthentication.Strategy.OAuth2.UserResolver.reso…
- CVE-2026-91039CRITICALCVSS 9.1EG 9.1fixed in 5.0.0-rc.142026-09-17
vulnerable: 5.0.0-rc.10, 5.0.0-rc.11, 5.0.0-rc.12, 5.0.0-rc.13
Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be signed in as a local user established through a different …
Check whether ash_authentication is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ash_authentication CVEs against the assets you own.
Book a Demo →