PT-2026-94297 · Unknown · Ashauthentication
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash authentication versions 4.8.0 through 4.14.9
ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description
An inefficient algorithmic complexity issue allows an unauthenticated attacker to cause CPU and memory exhaustion by submitting an API key with an oversized base62 segment. The function
AshAuthentication.Base.decode62/1 in lib/ash authentication/base.ex processes arguments by splitting them into binaries per character and using charval62/2, which recomputes Integer.pow(62, index) at every position. This results in a cubic growth in cost relative to input length. Additionally, the bindecode62/1 function exhibits quadratic growth due to the use of Integer.undigits/2 and Integer.digits/2. Because AshAuthentication.Strategy.ApiKey.SignInPreparation processes underscore-separated segments of the submitted key without capping byte size/1 or requiring prior authentication, the system is susceptible to resource exhaustion that cannot be mitigated by existing rescue clauses.Recommendations
Update ash authentication to version 4.15.0 or later.
Update ash authentication to version 5.0.0-rc.14 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ashauthentication