CVE-2026-82756
Last modified
CVE-2026-82756 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. BearerPlug and RequireScopePlug built the Bearer resource_metadata="..." challenge by interpolating a resource_metadata URL derived from the request tenant directly into the quoted value. In a multi-tenant application that sets the Ash tenant from request-controlled data (a subdomain, the Host, a path segment, or a header), a tenant containing a " closes the quoted value and appends attacker-chosen auth-params, including a second resource_metadata URL pointing at an attacker-controlled authorization server that spec-following clients follow. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. BearerPlug and RequireScopePlug built the Bearer resource_metadata="..." challenge by interpolating a resource_metadata URL derived from the request tenant directly into the quoted value. In a multi-tenant application that sets the Ash tenant from request-controlled data (a subdomain, the Host, a path segment, or a header), a tenant containing a " closes the quoted value and appends attacker-chosen auth-params, including a second resource_metadata URL pointing at an attacker-controlled authorization server that spec-following clients follow. Carriage returns and line feeds are rejected by Plug, so this is parameter injection within one header, not response splitting. This issue affects ash_authentication_oauth2_server: from 0.1.3 before 0.3.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ash-project | ash_authentication_oauth2_server | >= 0.1.3, < 0.3.1 |
| ash-project | ash_authentication_oauth2_server | >= 99de0a1cacb5ef667c4533278b7c81ca98c00231, < 09f97476715da031b136eaec7b2cda2363ad8149 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-82756?
How severe is CVE-2026-82756?
How do I fix CVE-2026-82756?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-82750Improper Validation of Specified Quantity in Input in ZenHiv…8.3
- CVE-2026-82751Improper Validation of Specified Quantity in Input in ZenHiv…8.3
- CVE-2026-82752Improper Validation of Specified Quantity in Input vulnerabi…5.9
- CVE-2026-82753Allocation of Resources Without Limits or Throttling vulnera…8.2
- CVE-2026-82754Improper Protection of Alternate Path vulnerability in ash-p…6.3
- CVE-2026-82755Use of Cache Containing Sensitive Information vulnerability …6.3
- CVE-2026-82757Server-Side Request Forgery (SSRF) vulnerability in ash-proj…6.3
- CVE-2026-82758Improper Authentication vulnerability in ash-project ash_aut…6.3
- CVE-2026-82759Use of a One-Way Hash with a Predictable Salt vulnerability …1.8
- CVE-2026-8276A flaw has been found in bettercap up to 2.41.5. Affected by…3.7
- CVE-2026-82760Inefficient Algorithmic Complexity vulnerability in team-ale…8.2
- CVE-2026-82761Time-of-check Time-of-use (TOCTOU) Race Condition vulnerabil…9.1
Are you affected by CVE-2026-82756?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
