EEF-CVE-2026-82757
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
Quick fix
EEF-CVE-2026-82757 — ash_authentication_oauth2_server: upgrade to the fixed version with the command below.
mix deps.update ash_authentication_oauth2_serverDetails
## Summary
Server-Side Request Forgery (SSRF) vulnerability in ash-project ash\_authentication\_oauth2\_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses.
public\_ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy for CIMD metadata fetches. It classified several address forms as publicly routable that are not: IPv4-compatible ::/96 (for example ::127.0.0.1), SIIT IPv4-translated ::ffff:0:0:0/96, and deprecated site-local fec0::/10. A returned AAAA record in one of these ranges passed the policy, so a fetch pinned to that address reached space the policy was meant to block.
This issue affects ash\_authentication\_oauth2\_server: from 0.3.0 before 0.3.1.
## Configuration
Reachable only when Client ID Metadata Documents are enabled (cimd\_enabled?: true), so the authorize endpoint fetches attacker-suppliable metadata URLs, and an internal or loopback target resolves to one of the affected IPv6 address forms.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.3.0Fixed in: 0.3.1mix deps.update ash_authentication_oauth2_serverReferences
- https://github.com/ash-project/ash_authentication_oauth2_server/security/advisories/GHSA-wprp-8gvj-p6cv[ADVISORY]
- https://cna.erlef.org/cves/CVE-2026-82757.html[WEB]
- https://github.com/ash-project/ash_authentication_oauth2_server/commit/268b591261a3473ab9b87272963e4dd2fd99d972[FIX]
- https://hex.pm/packages/ash_authentication_oauth2_server[PACKAGE]