Ash · Ash Authentication Oauth2 Server · CVE-2026-82754
## Summary
Improper Protection of Alternate Path vulnerability in ash-project ash authentication oauth2 server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix.
`oauth2 server protocol routes/1` in `AshAuthentication.Phoenix.Oauth2Server.Router` forwards the same `ProtocolRouter` at both the `/oauth` prefix and the `/.well-known` prefix. Phoenix `forward` strips the matched prefix before dispatch, so the full route table answers under both mounts, and `POST /register`, `POST /token`, and `POST /revoke` are reachable as `/.well-known/register`, `/.well-known/token`, and `/.well-known/revoke`. Edge controls such as WAF rules, rate limits, or authentication exemptions written against the `/oauth` paths, or that allow-list `/.well-known` as unauthenticated, do not apply to the alias.
This issue affects ash authentication oauth2 server: from 0.1.0 before 0.3.1.
## Configurations
The routing alias is unconditional. Exploitable impact depends on the deployment applying path-scoped edge controls (WAF, rate limiting, auth-redirect exemptions) to the `/oauth` prefix, or allow-listing `/.well-known` as unauthenticated, that the alias then bypasses.