Improper Verification of Cryptographic Signature in AshAuthentication by Team Alembic
CVE-2026-78223
What is CVE-2026-78223?
A vulnerability in the AshAuthentication library allows an attacker to exploit improper verification of cryptographic signatures during token revocation. Specifically, the function responsible for revoking tokens fails to perform a necessary signature check, allowing the attacker to neutralize revocation actions or to write arbitrary values into the token resource. By manipulating token attributes such as the expiration time, a forged token can appear to be valid, potentially re-enabling access to restricted resources. This issue affects specific versions of AshAuthentication, necessitating prompt updates to secure implementations.
Affected Version(s)
ash_authentication 0.2.0 < 4.15.0
ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14
ash_authentication a939dde9b917c072cdf10c4b0913a9886a4b0231
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
