ash_authentication
Hex17 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ash_authenticationpage 1 of 1
- CVE-2025-25202MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.4.92025-02-11
vulnerable: 4.1.0 ... 4.4.8 (31 versions)
Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present since AshAuthentication v4.1.0 and who have used the magic link strategy _or_ are manuall…
- CVE-2025-32782MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.7.02025-04-15
vulnerable: 3.0.3 ... 4.6.4 (116 versions)
Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently uses a GET request triggered by clicking a link sent via email. Some email clients and security tools (e.g., Outlook, vi…
- CVE-2026-49757CRITICALCVSS 9.2EG 9.2✓ Fixed in 5.0.0-rc.102026-06-15
vulnerable: 5.0.0-rc.0 ... 5.0.0-rc.9 (10 versions)
Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via OAuth2/OIDC sign-in. AshAuthentication's OAuth2 and OIDC family strategies matched the local user by email addres…
- CVE-2026-65633HIGHCVSS 7.6EG 7.6✓ Fixed in 5.0.0-rc.132026-08-25
vulnerable: 3.10.5 ... 5.0.0-rc.9 (131 versions)
Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification. The bearer-token authentication he…
- CVE-2026-66882LOWCVSS 2.1EG 2.1✓ Fixed in 5.0.0-rc.132026-08-25
vulnerable: 4.10.0 ... 5.0.0-rc.9 (43 versions)
Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows reflected cross-site scripting via the confirmation and magic link interaction forms. When a strategy is configured w…
- CVE-2026-76949CRITICALCVSS 9.1EG 9.1✓ Fixed in 5.0.0-rc.142026-09-17
vulnerable: 4.10.0 ... 5.0.0-rc.9 (28 versions)
Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for the attacker's own a…
- CVE-2026-78223MEDIUMCVSS 6.9EG 6.9✓ Fixed in 5.0.0-rc.142026-09-17
vulnerable: 3.0.3 ... 5.0.0-rc.9 (168 versions)
Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource. AshAuthentication.…
- CVE-2026-81632HIGHCVSS 7.2EG 7.2✓ Fixed in 5.0.0-rc.142026-09-17
vulnerable: 3.10.5 ... 5.0.0-rc.9 (133 versions)
Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its own…
- CVE-2026-81637LOWCVSS 2.3EG 2.3✓ Fixed in 5.0.0-rc.142026-09-17
vulnerable: 3.0.3 ... 5.0.0-rc.9 (168 versions)
Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attacker-controlled account. AshAuthenticatio…
- CVE-2026-82759LOWCVSS 1.8EG 1.8✓ Fixed in 5.0.0-rc.142026-09-17
vulnerable: 4.12.0 ... 5.0.0-rc.9 (26 versions)
Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover the client IP addresses that the audit log add-on's :hash privacy mode is meant to pseudonymise. As…
- CVE-2026-82760HIGHCVSS 8.2EG 8.2✓ Fixed in 5.0.0-rc.142026-09-17
vulnerable: 4.10.0 ... 5.0.0-rc.9 (45 versions)
Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an oversized base62 segment in a submitted API key. AshAuthentication.Base.decode62/1 in l…
- CVE-2026-82761CRITICALCVSS 9.1EG 9.1✓ Fixed in 5.0.0-rc.142026-09-17
vulnerable: 3.10.0 ... 5.0.0-rc.9 (145 versions)
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as the target subject. A magic link configured…
- CVE-2026-85500CRITICALCVSS 9.1EG 9.1✓ Fixed in 5.0.0-rc.142026-09-17
vulnerable: 4.10.0 ... 5.0.0-rc.9 (79 versions)
Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.ch…
- CVE-2026-86522MEDIUMCVSS 6.3EG 6.3✓ Fixed in 5.0.0-rc.142026-09-17
vulnerable: 4.10.0 ... 5.0.0-rc.9 (95 versions)
Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or control characters. …
- CVE-2026-86533CRITICALCVSS 9.1EG 9.1✓ Fixed in 5.0.0-rc.142026-09-17
vulnerable: 4.10.0 ... 5.0.0-rc.9 (37 versions)
Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_pre…
- CVE-2026-86688HIGHCVSS 7.4EG 7.4✓ Fixed in 5.0.0-rc.142026-09-17
vulnerable: 3.0.3 ... 5.0.0-rc.9 (168 versions)
Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs in. AshAuthentication.Plug.Helpers.store…
- CVE-2026-91039CRITICALCVSS 9.1EG 9.1✓ Fixed in 5.0.0-rc.142026-09-17
vulnerable: 5.0.0-rc.10, 5.0.0-rc.11, 5.0.0-rc.12, 5.0.0-rc.13
Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be signed in as a local user established through a different …
Check whether ash_authentication is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ash_authentication CVEs against the assets you own.
Start Free Scan →