Server-Side Request Forgery Flaw in ash_authentication_oauth2_server by Ash Project
CVE-2026-82757
6.3MEDIUM
Key Information:
- Vendor
Ash-project
- Vendor
- CVE Published:
- 7 September 2026
What is CVE-2026-82757?
The ash_authentication_oauth2_server has a Server-Side Request Forgery (SSRF) vulnerability that allows attackers to manipulate client metadata URLs. This vulnerability enables unauthorized connections to internal or loopback addresses, undermining the security measures intended to safeguard the server. Specifically, certain address forms, including deprecated and IPv4-compatible addresses, are incorrectly classified as publicly routable by the outbound policy, paving the way for potential exploitation.
Affected Version(s)
ash_authentication_oauth2_server 0.3.0 < 0.3.1
ash_authentication_oauth2_server e713a9ba816761140c226e2ca55b75c0b93f5984 < 268b591261a3473ab9b87272963e4dd2fd99d972
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
