CVE-2026-82756

MEDIUM CVSS 4.0: 6.3 EPSS 0.68%
Updated Sep 08, 2026
Ash-Project
Parameter Value
CVSS 6.3 (MEDIUM)
Affected Versions 0.1.3 — 0.3.1
Fixed In 0.3.1
Type CWE-116 (Improper Encoding or Escaping of Output)
Vendor Ash-Project
Public PoC No

Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. BearerPlug and RequireScopePlug built the Bearer resource_metadata="..." challenge by interpolating a resource_metadata URL derived from the request tenant directly into the quoted value. In a multi-tenant application that sets the Ash tenant from request-controlled data (a subdomain, the Host, a path segment, or a header), a tenant containing a " closes the quoted value and appends attacker-chosen auth-params, including a second resource_metadata URL pointing at an attacker-controlled authorization server that spec-following clients follow. Carriage returns and line feeds are rejected by Plug, so this is parameter injection within one header, not response splitting.

This issue affects ash_authentication_oauth2_server: from 0.1.3 before 0.3.1.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Ash-Project Ash_Authentication_Oauth2_Server
cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*
0.1.3 0.3.1