Information Exposure Vulnerability in ash-project’s OAuth 2.0 Server
CVE-2026-82755
Key Information:
- Vendor
Ash-project
- Vendor
- CVE Published:
- 7 September 2026
What is CVE-2026-82755?
The ash_authentication_oauth2_server contains a vulnerability that allows sensitive OAuth discovery metadata to be cached and improperly shared across tenants. When clients of one tenant make requests, they may inadvertently receive data intended for another tenant. The metadata endpoints provide critical tenant-specific values, which are incorrectly served with a public cache configuration. This misconfiguration results in a scenario where, if a shared HTTP cache is in use, cached responses for one tenant could be served to clients of another for up to an hour. Consequently, this issue raises significant concerns regarding the integrity of sensitive authorization data and can lead to incorrect token submissions and validation against unintended endpoints.
Affected Version(s)
ash_authentication_oauth2_server 0.1.3 < 0.3.1
ash_authentication_oauth2_server 99de0a1cacb5ef667c4533278b7c81ca98c00231 < 768d87f70e4e97ae1d2bf1606b5bf3f4d03f24a1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
