PT-2026-94297 · Unknown · Ashauthentication

·

CVE-2026-82760

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash authentication versions 4.8.0 through 4.14.9 ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description An inefficient algorithmic complexity issue allows an unauthenticated attacker to cause CPU and memory exhaustion by submitting an API key with an oversized base62 segment. The function AshAuthentication.Base.decode62/1 in lib/ash authentication/base.ex processes arguments by splitting them into binaries per character and using charval62/2, which recomputes Integer.pow(62, index) at every position. This results in a cubic growth in cost relative to input length. Additionally, the bindecode62/1 function exhibits quadratic growth due to the use of Integer.undigits/2 and Integer.digits/2. Because AshAuthentication.Strategy.ApiKey.SignInPreparation processes underscore-separated segments of the submitted key without capping byte size/1 or requiring prior authentication, the system is susceptible to resource exhaustion that cannot be mitigated by existing rescue clauses.
Recommendations Update ash authentication to version 4.15.0 or later. Update ash authentication to version 5.0.0-rc.14 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82760
GHSA-Q876-XR24-2MCX

Affected Products

Ashauthentication