PT-2026-86927 · Ash+1 · Ash Authentication Oauth2 Server

·

CVE-2026-82757

·

Published

2026-09-07

·

Updated

2026-09-07

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N

Summary

Server-Side Request Forgery (SSRF) vulnerability in ash-project ash authentication oauth2 server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses.
public ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy for CIMD metadata fetches. It classified several address forms as publicly routable that are not: IPv4-compatible ::/96 (for example ::127.0.0.1), SIIT IPv4-translated ::ffff:0:0:0/96, and deprecated site-local fec0::/10. A returned AAAA record in one of these ranges passed the policy, so a fetch pinned to that address reached space the policy was meant to block.
This issue affects ash authentication oauth2 server: from 0.3.0 before 0.3.1.

Configurations

Reachable only when Client ID Metadata Documents are enabled (cimd enabled?: true), so the authorize endpoint fetches attacker-suppliable metadata URLs, and an internal or loopback target resolves to one of the affected IPv6 address forms.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82757
GHSA-WPRP-8GVJ-P6CV

Affected Products

Ash Authentication Oauth2 Server