Improper Encoding in Ash Authentication OAuth2 Server Affects Ash Project
CVE-2026-82756
Key Information:
- Vendor
Ash-project
- Vendor
- CVE Published:
- 7 September 2026
What is CVE-2026-82756?
The Ash Project's ash_authentication_oauth2_server contains a vulnerability that permits unauthenticated attackers to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. This vulnerability arises from improper encoding during the construction of the Bearer resource_metadata challenge, where unvalidated data derived from request parameters allows for injections leading to potential manipulation of authentication flows. Attackers can exploit this flaw in multi-tenant environments by crafting subdomains or headers to close quoted values, inserting harmful parameters, including references to unauthorized authorization servers. This issue particularly affects versions from 0.1.3 to before 0.3.1.
Affected Version(s)
ash_authentication_oauth2_server 0.1.3 < 0.3.1
ash_authentication_oauth2_server 99de0a1cacb5ef667c4533278b7c81ca98c00231 < 09f97476715da031b136eaec7b2cda2363ad8149
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
