Insufficient Session Expiration in AshAuthentication by Team Alembic
CVE-2026-81637
What is CVE-2026-81637?
An insufficient session expiration vulnerability in AshAuthentication enables attackers to exploit an OAuth2 state value, allowing them to replay the callback and sign the victim into a maliciously controlled account. This occurs because the session parameters are not cleared effectively on failure paths of the authentication process, allowing sensitive data to persist beyond intended usage. Versions from ash_authentication 0.6.0 up to but not including 4.15.0, and versions from 5.0.0-rc.0 to below 5.0.0-rc.14 are affected. Developers are encouraged to review security patches and ensure robust session management to mitigate risks.
Affected Version(s)
ash_authentication 0.6.0 < 4.15.0
ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14
ash_authentication c5f589058e04239263f50a1430eb17ea6d5dd1a2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
