Server-Side Request Forgery Flaw in ash_authentication_oauth2_server by Ash Project
CVE-2026-82757

6.3MEDIUM

Key Information:

Vendor
CVE Published:
7 September 2026

What is CVE-2026-82757?

The ash_authentication_oauth2_server has a Server-Side Request Forgery (SSRF) vulnerability that allows attackers to manipulate client metadata URLs. This vulnerability enables unauthorized connections to internal or loopback addresses, undermining the security measures intended to safeguard the server. Specifically, certain address forms, including deprecated and IPv4-compatible addresses, are incorrectly classified as publicly routable by the outbound policy, paving the way for potential exploitation.

Affected Version(s)

ash_authentication_oauth2_server 0.3.0 < 0.3.1

ash_authentication_oauth2_server e713a9ba816761140c226e2ca55b75c0b93f5984 < 268b591261a3473ab9b87272963e4dd2fd99d972

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.