PT-2026-83690 · Unknown · Ash Phoenix
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ash phoenix versions 2.1.26 through 2.3.24
Description
A permissive regular expression in the
get subdomain/2 function allows a remote client to select the tenant an application uses or degrade the request by sending a crafted Host header. The issue occurs because the root host is interpolated raw into a regular expression, causing characters like dots to act as wildcards and allowing matches to be removed from anywhere in the string. Additionally, the comparison is case-sensitive, allowing certain host formats to bypass the root-host allowlist. This affects applications using subdomain-based multitenancy via get subdomain/2 (such as through AshPhoenix.LiveView.SubdomainHook) to select the tenant from the request host.Recommendations
Update ash phoenix to version 2.3.25 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ash Phoenix