VDB
Sign up

EEF-CVE-2026-82757

ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF

Quick fix

EEF-CVE-2026-82757 — ash_authentication_oauth2_server: upgrade to the fixed version with the command below.

mix deps.update ash_authentication_oauth2_server

Details

## Summary

Server-Side Request Forgery (SSRF) vulnerability in ash-project ash\_authentication\_oauth2\_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses.

public\_ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy for CIMD metadata fetches. It classified several address forms as publicly routable that are not: IPv4-compatible ::/96 (for example ::127.0.0.1), SIIT IPv4-translated ::ffff:0:0:0/96, and deprecated site-local fec0::/10. A returned AAAA record in one of these ranges passed the policy, so a fetch pinned to that address reached space the policy was meant to block.

This issue affects ash\_authentication\_oauth2\_server: from 0.3.0 before 0.3.1.

## Configuration

Reachable only when Client ID Metadata Documents are enabled (cimd\_enabled?: true), so the authorize endpoint fetches attacker-suppliable metadata URLs, and an internal or loopback target resolves to one of the affected IPv6 address forms.

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex/ash_authentication_oauth2_server
Introduced in: 0.3.0Fixed in: 0.3.1
Fixmix deps.update ash_authentication_oauth2_server

References