Improper Encoding in Ash Authentication OAuth2 Server Affects Ash Project
CVE-2026-82756

6.3MEDIUM

Key Information:

Vendor
CVE Published:
7 September 2026

What is CVE-2026-82756?

The Ash Project's ash_authentication_oauth2_server contains a vulnerability that permits unauthenticated attackers to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. This vulnerability arises from improper encoding during the construction of the Bearer resource_metadata challenge, where unvalidated data derived from request parameters allows for injections leading to potential manipulation of authentication flows. Attackers can exploit this flaw in multi-tenant environments by crafting subdomains or headers to close quoted values, inserting harmful parameters, including references to unauthorized authorization servers. This issue particularly affects versions from 0.1.3 to before 0.3.1.

Affected Version(s)

ash_authentication_oauth2_server 0.1.3 < 0.3.1

ash_authentication_oauth2_server 99de0a1cacb5ef667c4533278b7c81ca98c00231 < 09f97476715da031b136eaec7b2cda2363ad8149

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.