Permissive Regular Expression Vulnerability in Ash Phoenix by Ash Project
CVE-2026-82726
What is CVE-2026-82726?
The vulnerability in Ash Phoenix allows a remote attacker to exploit a permissive regular expression matching mechanism. By crafting a malicious Host header, an attacker can influence the tenant selection process of an Ash application, leading to unauthorized access or manipulation of the application’s behavior. This issue arises due to improper handling of the root domain in regular expressions, enabling wildcard-like behavior and bypassing security checks. The vulnerability affects versions of ash_phoenix prior to 2.3.25, making it essential for users to update to mitigate potential risks.
Affected Version(s)
ash_phoenix 2.1.26 < 2.3.25
ash_phoenix 9a5ea4d377bc263de321d79574872a3dfc4fb541 < 8306f29e77526840c89f3cd244996ce7c0fa2cda
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
