SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82757

MEDIUM · CVSS 6.3 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The ash_authentication_oauth2_server version 0.3.0 and earlier is vulnerable to a Server-Side Request Forgery (SSRF) attack, allowing an attacker controlling a client metadata URL to force the server to connect to internal or loopback addresses. This misclassification of certain address forms as publicly routable can lead to unauthorized access to sensitive internal resources. Organizations using this version of the software should prioritize patching to version 0.3.1 or later to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82757
Severity
MEDIUM
CVSS
6.3
EPSS
0.37%

Original NVD Description

Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses. public_ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy for CIMD metadata fetches. It classified several address forms as publicly routable that are not: IPv4-compatible ::/96 (for example ::127.0.0.1), SIIT IPv4-translated ::ffff:0:0:0/96, and deprecated site-local fec0::/10. A returned AAAA record in one of these ranges passed the policy, so a fetch pinned to that address reached space the policy was meant to block. This issue affects ash_authentication_oauth2_server: from 0.3.0 before 0.3.1.