PT-2026-83690 · Unknown · Ash Phoenix

·

CVE-2026-82726

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ash phoenix versions 2.1.26 through 2.3.24
Description A permissive regular expression in the get subdomain/2 function allows a remote client to select the tenant an application uses or degrade the request by sending a crafted Host header. The issue occurs because the root host is interpolated raw into a regular expression, causing characters like dots to act as wildcards and allowing matches to be removed from anywhere in the string. Additionally, the comparison is case-sensitive, allowing certain host formats to bypass the root-host allowlist. This affects applications using subdomain-based multitenancy via get subdomain/2 (such as through AshPhoenix.LiveView.SubdomainHook) to select the tenant from the request host.
Recommendations Update ash phoenix to version 2.3.25 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82726
GHSA-RPF8-Q9JH-QXRR

Affected Products

Ash Phoenix