Junglewise Threat Intelligence

CVE-2026-82754: ash-project ash_authentication_oauth2_server path traversal in OAuth endpoints

CVE-2026-82754 · Severity: info · Published 2026-09-07

Technologies: Ash-Project Ash Authentication Oauth2 Server. Vendors: Ash-Project.

Executive brief

ash_authentication_oauth2_server is an Elixir library that provides OAuth2 server functionality for web applications. A configuration flaw exposes OAuth endpoints (register, token, revoke) at an alternate path (/.well-known/) alongside their intended paths (/oauth/), allowing requests to bypass security controls like WAF rules and rate limits that are only applied to the canonical paths.

Technical details

This vulnerability stems from improper path protection in the Phoenix router configuration. The oauth2_server_protocol_routes function mounts the same ProtocolRouter at both /oauth and /.well-known prefixes. Because Phoenix strips the matched prefix before dispatching, the full OAuth route table (register, token, revoke) responds to both mount points. An attacker can reach state-changing OAuth operations at /.well-known/register, /.well-known/token, and /.well-known/revoke, circumventing edge controls such as WAF rules, authentication exemptions, or rate limits that are scoped only to the /oauth prefix. The vulnerability affects ash_authentication_oauth2_server versions 0.1.0 through 0.3.0; version 0.3.1 and later include a fix.

Affected products

  • ash-project ash_authentication_oauth2_server 0.1.0 to 0.3.0

Timeline

  • 2026-09-07: disclosed
  • 0.3.1: patched: Fix available in version 0.3.1 and later

References

Related threats