EEF-CVE-2026-82756

    Dashboard / Vulnerabilities / EEF-CVE-2026-82756

    EEF-CVE-2026-82756

    Published: 7 Sept 2026Last Modified: 7 Sept 2026

    Summary: ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection

    Details: ## Summary Improper Encoding or Escaping of Output vulnerability in ash-project ash\_authentication\_oauth2\_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. BearerPlug and RequireScopePlug built the Bearer resource\_metadata="..." challenge by interpolating a resource\_metadata URL derived from the request tenant directly into the quoted value. In a multi-tenant application that sets the Ash tenant from request-controlled data (a subdomain, the Host, a path segment, or a header), a tenant containing a " closes the quoted value and appends attacker-chosen auth-params, including a second resource\_metadata URL pointing at an attacker-controlled authorization server that spec-following clients follow. Carriage returns and line feeds are rejected by Plug, so this is parameter injection within one header, not response splitting. This issue affects ash\_authentication\_oauth2\_server: from 0.1.3 before 0.3.1. ## Configuration Reachable only in a multi-tenant application that derives the Ash tenant from request-controlled input (subdomain, Host, path, or header) and uses BearerPlug or RequireScopePlug; the tenant reaches the challenge through the server's tenant-aware resource\_url.

    Affected packages

    Package

    Name: ash_authentication_oauth2_server

    Purl: pkg:hex/ash_authentication_oauth2_server

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.1.3
    Fixed -0.3.1

    Affected versions

    0.1.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High