Team-Alembic Ash Authentication vulnerabilities
21 known vulnerabilities affecting team-alembic/ash_authentication.
Total CVEs
21
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH6MEDIUM4LOW4
Vulnerabilities
Page 1 of 2
CVE-2026-85500P2CRITICALCVSS 9.1≥ 4.3.8, < 4.15.0≥ 5.0.0-rc.0, < 5.0.0-rc.14+1 more2026-09-17
CVE-2026-85500 [CRITICAL] CWE-305 CVE-2026-85500: Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an
Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement.
AshAuthentication.Strategy.Password.Actions.check_user/2 decides whether the attribute named by require_confirmed_with is set using a bare is_nil(Map.get(use
nvd
CVE-2026-88952P2CRITICALCVSS 9.1≥ 4.14.0, < 4.15.0≥ 5.0.0-rc.10, < 5.0.0-rc.14+2 more2026-09-17
CVE-2026-88952 [CRITICAL] CWE-287 CVE-2026-88952: Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be sig
Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an OAuth2 identity to an account that is not theirs.
AshAuthentication.Strategy.OAuth2.UserResolver.resolve/3 matches an existing account using the register action's upsert_identity keys, then gates linking the inc
nvd
CVE-2026-76949P2CRITICALCVSS 9.1≥ 4.10.0, < 4.15.0≥ 5.0.0-rc.0, < 5.0.0-rc.14+1 more2026-09-17
CVE-2026-76949 [CRITICAL] CWE-290 CVE-2026-76949: Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacke
Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for the attacker's own account.
AshAuthentication.Plug.Helpers.sign_in_using_remember_me/3 skips re-authenticating an already-signed-
nvd
CVE-2026-49757P3CRITICALCVSS 9.2≥ 0.1.0, < 4.14.0≥ 5.0.0-rc.0, < 5.0.0-rc.10+1 more2026-06-15
CVE-2026-49757 [CRITICAL] CWE-290 CVE-2026-49757: Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account tak
Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via OAuth2/OIDC sign-in.
AshAuthentication's OAuth2 and OIDC family strategies matched the local user by email address (an upsert on the email field, or a user-defined sign-in filter) rather than by the OpenID Connect iss/sub c
ghsanvd
CVE-2026-91039P3CRITICALCVSS 9.1≥ 5.0.0-rc.10, < 5.0.0-rc.14≥ 64530644f9b37ebb76ca14aeb83a77597a0034b7, < 73ad16e452670bbf843550a13361bd41e72ad9642026-09-17
CVE-2026-91039 [CRITICAL] CWE-290 CVE-2026-91039: Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacke
Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be signed in as a local user established through a different connection.
The strategy is meant to keep each connection in its own identity namespace by writing every User
nvd
CVE-2026-82760P3HIGHCVSS 8.2≥ 4.8.0, < 4.15.0≥ 5.0.0-rc.0, < 5.0.0-rc.14+1 more2026-09-17
CVE-2026-82760 [HIGH] CWE-407 CVE-2026-82760: Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthe
Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an oversized base62 segment in a submitted API key.
AshAuthentication.Base.decode62/1 in lib/ash_authentication/base.ex splits its argument into one binary per character and folds it with charval62/2, whi
nvd
CVE-2026-86533P3CRITICALCVSS 9.1≥ 4.9.1, < 4.15.0≥ 5.0.0-rc.0, < 5.0.0-rc.14+1 more2026-09-17
CVE-2026-86533 [CRITICAL] CWE-613 CVE-2026-86533: Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthenticatio
Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated.
A resource configured with session_identifier :jti and require_token_presence_for_authentication? disabled stores its session value as :. The jti is there so that signing out can rev
nvd
CVE-2026-82761P3CRITICALCVSS 9.1≥ 3.9.0, < 4.15.0≥ 5.0.0-rc.0, < 5.0.0-rc.14+1 more2026-09-17
CVE-2026-82761 [CRITICAL] CWE-367 CVE-2026-82761: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication al
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as the target subject. A magic link configured with single_use_token?, which is the default, is meant to be redeemable exactly once, but nothing serialises
nvd
CVE-2026-80218P3HIGHCVSS 7.6≥ 3.10.5, < 4.15.0≥ 5.0.0-rc.0, < 5.0.0-rc.14+1 more2026-09-17
CVE-2026-80218 [HIGH] CWE-287 CVE-2026-80218: Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a
Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource.
AshAuthentication.Strategy.Password.SignInWithTokenPreparation.extract_primary_keys_from_subject/2 parses the JWT sub claim (for example user?id=1) with UR
nvd
CVE-2026-82685P3HIGHCVSS 7.6≥ 0.5.0, < 4.15.0≥ 5.0.0-rc.0, < 5.0.0-rc.14+1 more2026-09-17
CVE-2026-82685 [HIGH] CWE-639 CVE-2026-82685: Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication all
Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over that account. A confirmation token issued to one user is accepted on any other user's record.
AshAuthentication.AddOn.Confirmation.ConfirmChange verif
nvd
CVE-2026-65633P3HIGHCVSS 7.6≥ 3.10.5, < 4.14.2≥ 5.0.0-rc.0, < 5.0.0-rc.13+1 more2026-08-25
CVE-2026-65633 [HIGH] CWE-287 CVE-2026-65633: Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs
Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification.
The bearer-token authentication helper AshAuthentication.Plug.Helpers.retrieve_from_bearer/3 verifies an Authorization: Bearer JWT's signature and re
nvd
CVE-2026-86688P3HIGHCVSS 7.4≥ 0.2.0, < 4.15.0≥ 5.0.0-rc.0, < 5.0.0-rc.14+1 more2026-09-17
CVE-2026-86688 [HIGH] CWE-384 CVE-2026-86688: Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a
Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs in.
AshAuthentication.Plug.Helpers.store_in_session/2 writes the authenticated subject into the existing session with Plug.Conn.put_session/3 and never ca
nvd
CVE-2026-86522P3MEDIUMCVSS 6.3≥ 4.2.0, < 4.15.0≥ 5.0.0-rc.0, < 5.0.0-rc.14+1 more2026-09-17
CVE-2026-86522 [MEDIUM] CWE-117 CVE-2026-86522: Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an un
Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or control characters.
AshAuthentication.Strategy.Password.RequestPasswordReset.run/3 interpolates the identity argument, the email or
nvd
CVE-2026-78223P3MEDIUMCVSS 6.9≥ 0.2.0, < 4.15.0≥ 5.0.0-rc.0, < 5.0.0-rc.14+1 more2026-09-17
CVE-2026-78223 [MEDIUM] CWE-347 CVE-2026-78223: Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication all
Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource.
AshAuthentication.TokenResource.RevokeTokenChange.change/3 reads the :token argument and decodes it with AshAuthentication.Jwt.pee
nvd
CVE-2026-81632P3HIGHCVSS 7.2≥ 3.10.5, < 4.15.0≥ 5.0.0-rc.0, < 5.0.0-rc.14+1 more2026-09-17
CVE-2026-81632 [HIGH] CWE-598 CVE-2026-81632: Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoen
Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its owner.
After a successful password sign-in, AshAuthentication.Phoenix.Components.Password.SignInForm builds the sign
nvd
CVE-2025-25202P3MEDIUMCVSS 6.5v>= 4.1.0, < 4.4.92025-02-11
CVE-2025-25202 [MEDIUM] CWE-269 CVE-2025-25202: Ash Authentication is an authentication framework for Elixir applications. Applications which have b
Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present since AshAuthentication v4.1.0 and who have used the magic link strategy _or_ are manually revoking tokens are affected by revoked tokens being allowed to verify as valid. Unless one hase implemented a
ghsanvdosv
CVE-2025-32782P4MEDIUMCVSS 5.3fixed in 4.7.02025-04-15
CVE-2025-32782 [MEDIUM] CWE-306 CVE-2025-32782: Ash Authentication provides authentication for the Ash framework. The confirmation flow for account
Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently uses a GET request triggered by clicking a link sent via email. Some email clients and security tools (e.g., Outlook, virus scanners, and email previewers) may automatically follow these links, unintentionally confirming the account.
ghsanvdosv
CVE-2026-66882P4LOWCVSS 2.1≥ 4.8.0, < 4.14.2≥ 5.0.0-rc.0, < 5.0.0-rc.13+1 more2026-08-25
CVE-2026-66882 [LOW] CWE-79 CVE-2026-66882: Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshA
Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows reflected cross-site scripting via the confirmation and magic link interaction forms.
When a strategy is configured with require_interaction? set to true, AshAuthentication serves an intermediate HTML page asking the user to confirm
nvd
CVE-2026-81637P4LOWCVSS 2.3≥ 0.6.0, < 4.15.0≥ 5.0.0-rc.0, < 5.0.0-rc.14+1 more2026-09-17
CVE-2026-81637 [LOW] CWE-613 CVE-2026-81637: Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker w
Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attacker-controlled account.
AshAuthentication.Strategy.OAuth2.Plug.callback/2 clears the stored session_params through a rebinding step inside its with chain,
nvd
CVE-2026-82759P4LOWCVSS 1.8≥ 4.12.0, < 4.15.0≥ 5.0.0-rc.0, < 5.0.0-rc.14+1 more2026-09-17
CVE-2026-82759 [LOW] CWE-760 CVE-2026-82759: Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows
Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover the client IP addresses that the audit log add-on's :hash privacy mode is meant to pseudonymise.
AshAuthentication.AddOn.AuditLog.IpPrivacy.hash_ip/1 computes a single unkeyed :crypto.hash(:sha256, salt <> ip) and
nvd
1 / 2Next →