以下是该漏洞描述信息的中文翻译: Ash 项目中 ash_authentication_oauth2_server 组件存在服务器端请求伪造(SSRF)漏洞。如果攻击者能够控制客户端元数据 URL 及其 DNS 解析,就可以诱导服务器连接到内部地址或回环地址。 函数位于 中,负责强制执行 CIMD 元数据获取的出站策略。该函数错误地将几种非公共可路由的地址形式分类为公共可路由地址,具体包括:IPv4 兼容地址段 (例如 )、SIIT IPv4 转换地址段 ,以及已弃用的站点本地地址段 。当返回的 AAAA 记录落在
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash_authentication_oauth2_server | 0.3.0 ~ 0.3.1 |
cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*
|
|
| ash-project | ash_authentication_oauth2_server | e713a9ba816761140c226e2ca55b75c0b93f5984 ~ 268b591261a3473ab9b87272963e4dd2fd99d972 |
cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82753 | 8.2 HIGH | Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and c |
| CVE-2026-82586 | 8.2 HIGH | AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private at |
| CVE-2026-82755 | 6.3 MEDIUM | ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheab |
| CVE-2026-82758 | 6.3 MEDIUM | ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gat |
| CVE-2026-82754 | 6.3 MEDIUM | ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypas |
| CVE-2026-82756 | 6.3 MEDIUM | ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenti |
| CVE-2026-82584 | 2.3 LOW | Terminal escape sequence injection in the mix igniter.install confirmation prompt via pack |
| CVE-2026-81638 | 2.1 LOW | Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry |
No comments yet