ash_authentication_phoenix
Hex3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ash_authentication_phoenixpage 1 of 1
- CVE-2025-4754LOWCVSS 2.3EG 2.3fixed in 2.10.02025-06-17
vulnerable: 1.0.0 ... 2.9.0 (83 versions)
Insufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign-out to remain usable afterwards. The default sign_out/2 that AshAuthentication.Phoenix.Controller injects…
- CVE-2026-81632HIGHCVSS 7.2EG 7.2fixed in 2.17.4 or 3.0.0-rc.11, by version range2026-09-17
vulnerable: 1.7.0 ... 3.0.0-rc.9 (89 versions)
Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its own…
- CVE-2026-86533CRITICALCVSS 9.1EG 9.1fixed in 2.17.4 or 3.0.0-rc.11, by version range2026-09-17
vulnerable: 2.10.0 ... 3.0.0-rc.9 (30 versions)
Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_pre…
Check whether ash_authentication_phoenix is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ash_authentication_phoenix CVEs against the assets you own.
Book a Demo →