Junglewise Threat Intelligence

CVE-2026-82753: ash-project ash_authentication_oauth2_server unbound resource allocation in /authorize

CVE-2026-82753 · Severity: info · Published 2026-09-07

Technologies: Ash-Project Ash Authentication Oauth2 Server. Vendors: Ash-Project.

Executive brief

ash_authentication_oauth2_server is a library that provides OAuth 2.0 authentication for applications built with the Ash framework. An attacker can exploit an unprotected endpoint by providing many distinct client metadata URLs, causing the server to create unlimited database records and cache entries with no size or expiration limits, leading to denial of service through resource exhaustion.

Technical details

The vulnerability exists in the /authorize endpoint's resolve_client/3 function within the Client ID Metadata Document (CIMD) feature. When processing an unauthenticated request, the endpoint fetches and upserts a client row for each URL-shaped client_id without enforcing any limits on the number of rows, TTL-based cleanup, or field length validation. Additionally, fetched documents are cached before validation, allowing rejected documents to consume memory until cache expiration. An attacker can exploit this by serving valid OAuth 2.0 metadata documents from many distinct URLs, with multi-megabyte strings in document fields, causing unbounded growth of database storage and in-memory cache. The issue affects versions 0.3.0 through 0.3.0; a fix is available in version 0.3.1.

Affected products

  • ash-project ash_authentication_oauth2_server 0.3.0 before 0.3.1

Timeline

  • 2026-09-07: disclosed

References

Related threats