Improper Protection of Alternate Path Vulnerability in Ash-Project OAuth2 Server
CVE-2026-82754
Key Information:
- Vendor
Ash-project
- Vendor
- CVE Published:
- 7 September 2026
What is CVE-2026-82754?
The Ash-Project OAuth2 Server experiences an improper protection vulnerability, which allows state-changing OAuth endpoints to be reachable through unintended URL prefixes. This flaw arises because the same ProtocolRouter is forwarded at both the /oauth prefix and the /.well-known prefix. As a result, critical functionalities such as registering, token generation, and revocation become accessible at the unintended URLs: /.well-known/register, /.well-known/token, and /.well-known/revoke. Existing edge controls such as WAF rules and rate limits that are usually applied to the /oauth paths may not protect these endpoints, leading to potential unauthorized access.
Affected Version(s)
ash_authentication_oauth2_server 0.1.0 < 0.3.1
ash_authentication_oauth2_server 855b578037c5ded18e8a6e60f42e56bde4905fae
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
