Resource Exhaustion in ash_authentication_oauth2_server by Ash Project
CVE-2026-82753

8.2HIGH

Key Information:

Vendor
CVE Published:
7 September 2026

What is CVE-2026-82753?

The ash_authentication_oauth2_server is susceptible to resource exhaustion due to an allocation of resources without any imposed limits. Unauthenticated attackers can exploit this flaw via the /authorize endpoint, which allows fetching and upserting client rows without constraint. The system does not limit the number of rows created, leading to unregulated consumption of database storage and memory. Attackers can leverage this by providing valid documents from numerous distinct URLs, causing the server to create a permanent client row for each URL. This results in excessive storage and memory usage, which can severely impact the performance and availability of the affected service. A patch has been developed to address this vulnerability.

Affected Version(s)

ash_authentication_oauth2_server 0.3.0 < 0.3.1

ash_authentication_oauth2_server e713a9ba816761140c226e2ca55b75c0b93f5984 < 45e24f69e0f95d67413e2508acc2264156acb5ac

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.