Permissive Regular Expression Vulnerability in Ash Phoenix by Ash Project
CVE-2026-82726

6.3MEDIUM

Key Information:

Vendor
CVE Published:
31 August 2026

What is CVE-2026-82726?

The vulnerability in Ash Phoenix allows a remote attacker to exploit a permissive regular expression matching mechanism. By crafting a malicious Host header, an attacker can influence the tenant selection process of an Ash application, leading to unauthorized access or manipulation of the application’s behavior. This issue arises due to improper handling of the root domain in regular expressions, enabling wildcard-like behavior and bypassing security checks. The vulnerability affects versions of ash_phoenix prior to 2.3.25, making it essential for users to update to mitigate potential risks.

Affected Version(s)

ash_phoenix 2.1.26 < 2.3.25

ash_phoenix 9a5ea4d377bc263de321d79574872a3dfc4fb541 < 8306f29e77526840c89f3cd244996ce7c0fa2cda

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.