Description
Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses.

public_ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy for CIMD metadata fetches. It classified several address forms as publicly routable that are not: IPv4-compatible ::/96 (for example ::127.0.0.1), SIIT IPv4-translated ::ffff:0:0:0/96, and deprecated site-local fec0::/10. A returned AAAA record in one of these ranges passed the policy, so a fetch pinned to that address reached space the policy was meant to block.

This issue affects ash_authentication_oauth2_server: from 0.3.0 before 0.3.1.
Published: 2026-09-07
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Patch Upgrade
AI Analysis

Impact

The flaw allows an attacker who can control a client‑metadata URL and its DNS to force the application server to resolve IPv6 addresses that are actually internal, such as ::127.0.0.1 or fec0::/10, and then fetch data from those internal targets. This violates the intended outbound policy and permits the attacker to reach loopback or intranet services, potentially exfiltrating sensitive data or using the server as a pivot for deeper attacks. The weakness is a classic Server‑Side Request Forgery (CWE‑918).

Affected Systems

The vulnerability exists in ash-project ash_authentication_oauth2_server version 0.3.0 only. The CVE does not specify a fixed release, so vendors should verify that they are running a patched version.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. Although EPSS information is not provided and the vulnerability is not listed in the CISA KEV catalog, the remote nature of the SSRF makes exploitation plausible for an attacker who can manipulate the client‑metadata URL. The attack requires only the ability to supply a malicious URL to the server; no authentication is mentioned, implying that any user able to register or update client metadata could trigger it. Should the server expose internal resources, the impact could be significant, though the current scoring reflects a moderate risk level.

Generated by OpenCVE AI on September 8, 2026 at 00:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ash_authentication_oauth2_server to a patched version as provided by the vendor or official advisories.
  • If upgrading is not immediately possible, restrict the client‑metadata URLs to known public addresses or explicitly block IPv6 addresses that are <IPv4‑compatible>, <SIIT>, or <site‑local>; implement outbound filtering that rejects requests to internal IP ranges.
  • Audit and monitor outbound traffic from the authentication server for unexpected connections to private or loopback IP addresses, and consider applying network segmentation or firewall rules to limit the server’s ability to reach sensitive internal hosts.

Generated by OpenCVE AI on September 8, 2026 at 00:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses. public_ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy for CIMD metadata fetches. It classified several address forms as publicly routable that are not: IPv4-compatible ::/96 (for example ::127.0.0.1), SIIT IPv4-translated ::ffff:0:0:0/96, and deprecated site-local fec0::/10. A returned AAAA record in one of these ranges passed the policy, so a fetch pinned to that address reached space the policy was meant to block. This issue affects ash_authentication_oauth2_server: from 0.3.0 before 0.3.1.
Title ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
First Time appeared Ash-project
Ash-project ash Authentication Oauth2 Server
Weaknesses CWE-918
CPEs cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*
Vendors & Products Ash-project
Ash-project ash Authentication Oauth2 Server
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Ash-project Ash Authentication Oauth2 Server
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-08T14:43:57.511Z

Reserved: 2026-08-31T01:00:10.817Z

Link: CVE-2026-82757

cve-icon Vulnrichment

Updated: 2026-09-08T14:43:53.924Z

cve-icon NVD

Status : Deferred

Published: 2026-09-07T23:16:52.957

Modified: 2026-09-08T15:18:50.823

Link: CVE-2026-82757

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:36:37Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)