EEF-CVE-2026-82757

    Dashboard / Vulnerabilities / EEF-CVE-2026-82757

    EEF-CVE-2026-82757

    Published: 7 Sept 2026Last Modified: 7 Sept 2026

    Summary: ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF

    Details: ## Summary Server-Side Request Forgery (SSRF) vulnerability in ash-project ash\_authentication\_oauth2\_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses. public\_ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy for CIMD metadata fetches. It classified several address forms as publicly routable that are not: IPv4-compatible ::/96 (for example ::127.0.0.1), SIIT IPv4-translated ::ffff:0:0:0/96, and deprecated site-local fec0::/10. A returned AAAA record in one of these ranges passed the policy, so a fetch pinned to that address reached space the policy was meant to block. This issue affects ash\_authentication\_oauth2\_server: from 0.3.0 before 0.3.1. ## Configuration Reachable only when Client ID Metadata Documents are enabled (cimd\_enabled?: true), so the authorize endpoint fetches attacker-suppliable metadata URLs, and an internal or loopback target resolves to one of the affected IPv6 address forms.

    Affected packages

    Package

    Name: ash_authentication_oauth2_server

    Purl: pkg:hex/ash_authentication_oauth2_server

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.3.0
    Fixed -0.3.1

    Affected versions

    0.3.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High