CVE-2026-82757: CWE-918 Server-Side Request Forgery (SSRF) in ash-project ash_authentication_oauth2_server
CVE-2026-82757 is a Server-Side Request Forgery (SSRF) vulnerability in ash-project's ash_authentication_oauth2_server. It allows an attacker who controls a client metadata URL and its DNS to cause the server to connect to internal or loopback addresses. The vulnerability arises because the outbound policy enforcement misclassifies certain IPv6 address forms as publicly routable when they are not, allowing unauthorized internal network access. This affects versions 0.3.0 up to but not including 0.3.1.
AI Analysis
Technical Summary
The SSRF vulnerability in ash_authentication_oauth2_server stems from improper classification of IPv6 addresses in the public_ip?/1 function within AshAuthentication.Oauth2Server.CIMD.ReqFetcher. Specifically, IPv4-compatible (::/96), SIIT IPv4-translated (::ffff:0:0:0/96), and deprecated site-local (fec0::/10) IPv6 ranges were incorrectly treated as publicly routable. This flaw allowed an attacker controlling the client metadata URL and DNS to bypass outbound request policies and make the server connect to internal or loopback addresses, potentially exposing internal services. The issue affects versions from 0.3.0 before 0.3.1.
Potential Impact
An attacker with control over the client metadata URL and its DNS can exploit this vulnerability to make the server initiate connections to internal or loopback network addresses that should have been blocked. This could lead to unauthorized access or interaction with internal network resources that are normally inaccessible from outside, potentially exposing sensitive information or enabling further attacks within the internal network.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch has been documented at this time. Until a patch is available, users should consider restricting or validating client metadata URLs and DNS controls to trusted sources to mitigate risk.
CVE-2026-82757: CWE-918 Server-Side Request Forgery (SSRF) in ash-project ash_authentication_oauth2_server
Description
CVE-2026-82757 is a Server-Side Request Forgery (SSRF) vulnerability in ash-project's ash_authentication_oauth2_server. It allows an attacker who controls a client metadata URL and its DNS to cause the server to connect to internal or loopback addresses. The vulnerability arises because the outbound policy enforcement misclassifies certain IPv6 address forms as publicly routable when they are not, allowing unauthorized internal network access. This affects versions 0.3.0 up to but not including 0.3.1.
CVSS v4.0
Score 6.3medium
Affected software
pkg:hex/ash_authentication_oauth2_serverpkg:github/ash-project/ash_authentication_oauth2_servercpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The SSRF vulnerability in ash_authentication_oauth2_server stems from improper classification of IPv6 addresses in the public_ip?/1 function within AshAuthentication.Oauth2Server.CIMD.ReqFetcher. Specifically, IPv4-compatible (::/96), SIIT IPv4-translated (::ffff:0:0:0/96), and deprecated site-local (fec0::/10) IPv6 ranges were incorrectly treated as publicly routable. This flaw allowed an attacker controlling the client metadata URL and DNS to bypass outbound request policies and make the server connect to internal or loopback addresses, potentially exposing internal services. The issue affects versions from 0.3.0 before 0.3.1.
Potential Impact
An attacker with control over the client metadata URL and its DNS can exploit this vulnerability to make the server initiate connections to internal or loopback network addresses that should have been blocked. This could lead to unauthorized access or interaction with internal network resources that are normally inaccessible from outside, potentially exposing sensitive information or enabling further attacks within the internal network.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch has been documented at this time. Until a patch is available, users should consider restricting or validating client metadata URLs and DNS controls to trusted sources to mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- EEF
- Date Reserved
- 2026-08-31T01:00:10.817Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a9f4039acd9273b4972ed9d
Added to database: 09/07/2026, 22:52:41 UTC
Last enriched: 09/07/2026, 23:07:54 UTC
Last updated: 09/08/2026, 01:04:40 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.