目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-82760— AshAuthentication API 密钥登录资源耗尽漏洞

一分钟漏洞结论

影响对象
team-alembic ash_authentication
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

AshAuthentication 中的 team-alembic 模块存在“低效算法复杂度”漏洞:未认证的 attackers 可以通过在提交的 API Key 中嵌入一个超长的 base62 片段,从而耗尽 CPU 和内存资源。 具体而言, 中的 会将输入字符串按字符拆分为二元组,并通过 进行折叠处理。该方法在每个位置都重新计算 ,而未采用霍纳法则进行累积计算,导致处理时间随输入长度呈近似立方级增长。同一模块中的 因使用 和 ,其复杂度为平方级。这两个函数均未对 设置上限,而 会将提交的密钥中以下划线分隔的各段

CVSS 8.2 · High
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-82760 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in
来源: CVE Program / CVE List V5
Vulnerability Description
Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an oversized base62 segment in a submitted API key. AshAuthentication.Base.decode62/1 in lib/ash_authentication/base.ex splits its argument into one binary per character and folds it with charval62/2, which recomputes Integer.pow(62, index) at every position instead of accumulating by Horner's method, so cost grows roughly cubically in the input length. bindecode62/1 in the same module is quadratic through Integer.undigits/2 and Integer.digits/2. Neither function caps byte_size/1, and AshAuthentication.Strategy.ApiKey.SignInPreparation passes the underscore-separated segments of the submitted key straight into both, before any key lookup and without prior authentication. The surrounding rescue clauses catch exceptions, not CPU or memory exhaustion. This issue affects ash_authentication: from 4.8.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
算法复杂性
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
team-alembic ash_authentication 4.8.0 ~ 4.15.0 cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*
team-alembic ash_authentication f3a53f480088419788d5c3934af3131fa9066773 ~ * cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*

二、漏洞 CVE-2026-82760 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-82760 的情报信息

登录查看更多情报信息。

CVE-2026-82760 补丁与修复 (2)

CVE-2026-82760 厂商安全公告 (2)

CVE-2026-82760 厂商页面 (1)

同批安全公告 · team-alembic · 2026-09-17 · 共 14 条

CVE-2026-82761 9.1 CRITICAL AshAuthentication 令牌重放竞态漏洞
CVE-2026-86533 9.1 CRITICAL AshAuthentication Phoenix已吊销会话接收漏洞
CVE-2026-85500 9.1 CRITICAL Ash Authentication require_confirmed_with未强制校验漏洞
CVE-2026-88952 9.1 CRITICAL AshAuthentication OAuth2 账户链接逻辑缺陷
CVE-2026-91039 9.1 CRITICAL ash_authentication 动态 OIDC 跨连接账户接管漏洞
CVE-2026-82685 7.6 HIGH AshAuthentication 确认令牌通用漏洞
CVE-2026-80218 7.6 HIGH AshAuthentication 登录令牌跨资源复用漏洞
CVE-2026-81632 7.2 HIGH AshAuthenticationPhoenix 一次性令牌重定向泄露漏洞
CVE-2026-78223 6.9 MEDIUM AshAuthentication 凭据撤销记录 JWT 验证漏洞
CVE-2026-86522 6.3 MEDIUM AshAuthentication 日志注入漏洞
CVE-2026-81637 2.3 LOW AshAuthentication 2.0.0 重放式CSRF漏洞
CVE-2026-82723 1.8 LOW AshAuthentication 审计日志记录密码摘要
CVE-2026-82759 1.8 LOW AshAuthentication审计日志哈希模式IP脱敏可逆漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-82760

暂无评论


发表评论