Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-82758: CWE-287 Improper Authentication in ash-project ash_authentication_oauth2_serverCVE-2026-82758
0

CVE-2026-82758 is an improper authentication vulnerability in the ash_authentication_oauth2_server component of the ash-project. It allows unauthenticated attackers to register OAuth clients even when Dynamic Client Registration is intended to be restricted by an initial access token. The flaw arises because the secret resolution function treats empty or false values as valid secrets, causing the token check to pass without a valid token. This affects versions from 0.1.0 up to but not including 0.3.1.

Join the discussion
CVE-2026-82757: CWE-918 Server-Side Request Forgery (SSRF) in ash-project ash_authentication_oauth2_serverCVE-2026-82757
0

CVE-2026-82757 is a Server-Side Request Forgery (SSRF) vulnerability in ash-project's ash_authentication_oauth2_server. It allows an attacker who controls a client metadata URL and its DNS to cause the server to connect to internal or loopback addresses. The vulnerability arises because the outbound policy enforcement misclassifies certain IPv6 address forms as publicly routable when they are not, allowing unauthorized internal network access. This affects versions 0.3.0 up to but not including 0.3.1.

Join the discussion
CVE-2026-82756: CWE-116 Improper Encoding or Escaping of Output in ash-project ash_authentication_oauth2_serverCVE-2026-82756
0

CVE-2026-82756 is a medium severity vulnerability in ash-project's ash_authentication_oauth2_server affecting versions 0.1.3 up to but not including 0.3.1. It involves improper encoding or escaping of output, allowing an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. This occurs because certain plugs interpolate tenant-derived URLs directly into quoted header values without proper escaping, enabling parameter injection within a single header.

Join the discussion
CVE-2026-82753: CWE-770 Allocation of Resources Without Limits or Throttling in ash-project ash_authentication_oauth2_serverCVE-2026-82753
0

CVE-2026-82753 is a resource exhaustion vulnerability in ash-project's ash_authentication_oauth2_server. It allows an unauthenticated attacker to exhaust database storage and memory by abusing the /authorize endpoint when Client ID Metadata Documents are enabled. The vulnerability arises because the server creates permanent client rows for each distinct URL-shaped client_id without limits, expiry, or garbage collection, and stores large documents in cache even if rejected. This affects versions 0.3.0 up to but not including 0.3.1.

Join the discussion
CVE-2026-82755: CWE-524 Use of Cache Containing Sensitive Information in ash-project ash_authentication_oauth2_serverCVE-2026-82755
0

CVE-2026-82755 is a vulnerability in ash-project's ash_authentication_oauth2_server where sensitive OAuth discovery metadata is cached publicly and shared across tenants. This allows one tenant's metadata to be served to another tenant's clients due to improper cache control headers and lack of cache key variation. The issue affects versions from 0.1.3 up to but not including 0.3.1.

Join the discussion
CVE-2026-82754: CWE-424 Improper Protection of Alternate Path in ash-project ash_authentication_oauth2_serverCVE-2026-82754
0

CVE-2026-82754 is an improper protection of alternate path vulnerability in ash-project's ash_authentication_oauth2_server. The OAuth2 server routes are accessible under both the intended /oauth prefix and an unintended /.well-known prefix, allowing state-changing endpoints to bypass controls scoped only to the canonical /oauth path. This affects versions from 0.1.0 up to but not including 0.3.1.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:github/ash-project/ash_authentication_oauth2_server
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses