PT-2026-86927 · Ash+1 · Ash Authentication Oauth2 Server
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N |
Summary
Server-Side Request Forgery (SSRF) vulnerability in ash-project ash authentication oauth2 server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses.
public ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy for CIMD metadata fetches. It classified several address forms as publicly routable that are not: IPv4-compatible ::/96 (for example ::127.0.0.1), SIIT IPv4-translated ::ffff:0:0:0/96, and deprecated site-local fec0::/10. A returned AAAA record in one of these ranges passed the policy, so a fetch pinned to that address reached space the policy was meant to block.This issue affects ash authentication oauth2 server: from 0.3.0 before 0.3.1.
Configurations
Reachable only when Client ID Metadata Documents are enabled (
cimd enabled?: true), so the authorize endpoint fetches attacker-suppliable metadata URLs, and an internal or loopback target resolves to one of the affected IPv6 address forms.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash Authentication Oauth2 Server