Inefficient Algorithmic Complexity in Team-Alembic AshAuthentication Product
CVE-2026-82760

8.2HIGH

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-82760?

The AshAuthentication product from team-alembic exhibits a vulnerability stemming from inefficient algorithmic complexity. An unauthenticated attacker can exploit this flaw by submitting an oversized base62 segment in an API key, leading to excessive CPU and memory consumption. The vulnerability arises from the way the Base.decode62/1 function processes its input, recalculating integer values for each character in the input without efficient accumulation. This results in a substantially increased processing time, especially for longer input strings. The associated functions do not limit input size, allowing attackers to send requests that may cause resource exhaustion on the server.

Affected Version(s)

ash_authentication 4.8.0 < 4.15.0

ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14

ash_authentication f3a53f480088419788d5c3934af3131fa9066773

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
James Harton
Jonatan Männchen / EEF
.