Executive brief
AshAuthentication is a library used to handle user authentication and token management in Elixir applications. A vulnerability in the token revocation feature allows attackers to forge token revocation records by manipulating JWT claims without cryptographic verification, enabling them to neutralize legitimate revocations or insert fraudulent token records. This could allow attackers to bypass token revocation controls and maintain unauthorized access to applications.
Technical details
The vulnerability stems from improper cryptographic signature verification in AshAuthentication.TokenResource.RevokeTokenChange.change/3. The function decodes JWT tokens using Joken.peek_claims/1 (which returns claims without signature verification) instead of calling Jwt.verify/4 (which performs verification). An attacker can craft a forged JWT with a valid jti (JWT ID) but a backdated exp (expiration time) claim, causing the revocation record to appear already expired and be automatically removed by expunge_expired. Similarly, arbitrary jti and sub (subject) claims can be injected. The attack requires network access to the token revocation endpoint but no pre-existing authentication. Versions 0.2.0 through 4.14.x and 5.0.0-rc.0 through 5.0.0-rc.13 are affected; patched versions are 4.15.0 and 5.0.0-rc.14 or later.
Affected products
- team-alembic AshAuthentication 0.2.0 to 4.14.x, 5.0.0-rc.0 to 5.0.0-rc.13
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Patched in versions 4.15.0 and 5.0.0-rc.14