ash_authentication_oauth2_server
Hex6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ash_authentication_oauth2_serverpage 1 of 1
- CVE-2026-82753HIGHCVSS 8.2EG 8.2✓ Fixed in 0.3.12026-09-07
vulnerable: 0.3.0
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database storage and memory. The /authorize endpoint is unauthenticated by de…
- CVE-2026-82754MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.3.12026-09-07
vulnerable: 0.1.0 ... 0.3.0 (8 versions)
Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix. oauth2_serve…
- CVE-2026-82755MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.3.12026-09-07
vulnerable: 0.1.3, 0.2.0, 0.2.1, 0.2.2, 0.3.0
Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery metadata to another tenant's clients. The RFC 8414 and RFC 9728 m…
- CVE-2026-82756MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.3.12026-09-07
vulnerable: 0.1.3, 0.2.0, 0.2.1, 0.2.2, 0.3.0
Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. BearerPlug …
- CVE-2026-82757MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.3.12026-09-07
vulnerable: 0.3.0
Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses. public_ip?/1 …
- CVE-2026-82758MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.3.12026-09-07
vulnerable: 0.1.0 ... 0.3.0 (8 versions)
Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. resolve_secret/3…
Check whether ash_authentication_oauth2_server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ash_authentication_oauth2_server CVEs against the assets you own.
Start Free Scan →