VDB
Sign up

EEF-CVE-2026-78223

Token revocation record built from unverified JWT claims in AshAuthentication

Quick fix

EEF-CVE-2026-78223 — ash_authentication: upgrade to the fixed version with the command below.

mix deps.update ash_authentication

Details

## Summary

Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource.

`AshAuthentication.TokenResource.RevokeTokenChange.change/3` reads the `:token` argument and decodes it with `AshAuthentication.Jwt.peek/1`, which delegates to `Joken.peek_claims/1` and performs no signature check, unlike `Jwt.verify/4`. The `jti`, `exp` and `sub` claims it returns are written straight onto the revocation record, guarded only by `byte_size(token) > 0`. Because `expires_at` derives from the attacker-chosen `exp`, a forged copy of a genuine token that keeps the real `jti` but backdates `exp` yields a revocation row that is already expired: `expunge_expired` removes it and the genuine token passes `revoked?` again. Arbitrary `jti` and `sub` values can be inserted the same way.

This issue affects ash_authentication: from 0.2.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex/ash_authentication
Introduced in: 0.2.0Fixed in: 4.15.0
Fixmix deps.update ash_authentication

References