Resource Exhaustion in ash_authentication_oauth2_server by Ash Project
CVE-2026-82753
Key Information:
- Vendor
Ash-project
- Vendor
- CVE Published:
- 7 September 2026
What is CVE-2026-82753?
The ash_authentication_oauth2_server is susceptible to resource exhaustion due to an allocation of resources without any imposed limits. Unauthenticated attackers can exploit this flaw via the /authorize endpoint, which allows fetching and upserting client rows without constraint. The system does not limit the number of rows created, leading to unregulated consumption of database storage and memory. Attackers can leverage this by providing valid documents from numerous distinct URLs, causing the server to create a permanent client row for each URL. This results in excessive storage and memory usage, which can severely impact the performance and availability of the affected service. A patch has been developed to address this vulnerability.
Affected Version(s)
ash_authentication_oauth2_server 0.3.0 < 0.3.1
ash_authentication_oauth2_server e713a9ba816761140c226e2ca55b75c0b93f5984 < 45e24f69e0f95d67413e2508acc2264156acb5ac
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
