Information Exposure Vulnerability in ash-project’s OAuth 2.0 Server
CVE-2026-82755

6.3MEDIUM

Key Information:

Vendor
CVE Published:
7 September 2026

What is CVE-2026-82755?

The ash_authentication_oauth2_server contains a vulnerability that allows sensitive OAuth discovery metadata to be cached and improperly shared across tenants. When clients of one tenant make requests, they may inadvertently receive data intended for another tenant. The metadata endpoints provide critical tenant-specific values, which are incorrectly served with a public cache configuration. This misconfiguration results in a scenario where, if a shared HTTP cache is in use, cached responses for one tenant could be served to clients of another for up to an hour. Consequently, this issue raises significant concerns regarding the integrity of sensitive authorization data and can lead to incorrect token submissions and validation against unintended endpoints.

Affected Version(s)

ash_authentication_oauth2_server 0.1.3 < 0.3.1

ash_authentication_oauth2_server 99de0a1cacb5ef667c4533278b7c81ca98c00231 < 768d87f70e4e97ae1d2bf1606b5bf3f4d03f24a1

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.