Alembic
Alembic ASH Authentication: vulnerabilidades y CVE
Alembic ASH Authentication tiene 21 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses19
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86688 | Alta (7.4) | 0.74% | — | 17 sept 2026 | Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs in.… |
| CVE-2026-76949 | Crítica (9.1) | 0.77% | — | 17 sept 2026 | Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for… |
| CVE-2026-91039 | Crítica (9.1) | 0.66% | — | 17 sept 2026 | Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be signed in as a local user established… |
| CVE-2026-88952 | Crítica (9.1) | 0.75% | — | 17 sept 2026 | Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an OAuth2 identity to an account that is not theirs.… |
| CVE-2026-86533 | Crítica (9.1) | 0.91% | — | 17 sept 2026 | Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti… |
| CVE-2026-86522 | Media (6.3) | 0.74% | — | 17 sept 2026 | Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or… |
| CVE-2026-85500 | Crítica (9.1) | 0.77% | — | 17 sept 2026 | Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement.… |
| CVE-2026-82761 | Crítica (9.1) | 0.56% | — | 17 sept 2026 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as the target subject. A… |
| CVE-2026-82760 | Alta (8.2) | 0.74% | — | 17 sept 2026 | Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an oversized base62 segment in a submitted API key.… |
| CVE-2026-82759 | Baja (1.8) | 0.14% | — | 17 sept 2026 | Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover the client IP addresses that the audit log add-on's :hash privacy mode is meant… |
| CVE-2026-82723 | Baja (1.8) | 0.18% | — | 17 sept 2026 | Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's… |
| CVE-2026-82685 | Alta (7.6) | 0.66% | — | 17 sept 2026 | Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over that account. A… |
| CVE-2026-81637 | Baja (2.3) | 0.61% | — | 17 sept 2026 | Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attacker-controlled… |
| CVE-2026-81632 | Alta (7.2) | 0.21% | — | 17 sept 2026 | Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and… |
| CVE-2026-80218 | Alta (7.6) | 0.64% | — | 17 sept 2026 | Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource.… |
| CVE-2026-78223 | Media (6.9) | 0.44% | — | 17 sept 2026 | Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource.… |
| CVE-2026-66882 | Baja (2.1) | 0.75% | — | 25 ago 2026 | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows reflected cross-site scripting via the confirmation and magic link interaction forms. When a… |
| CVE-2026-65633 | Alta (7.6) | 0.58% | — | 25 ago 2026 | Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification. The… |
| CVE-2026-49757 | Crítica (9.2) | 0.68% | — | 15 jun 2026 | Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via OAuth2/OIDC sign-in. AshAuthentication's OAuth2 and OIDC family strategies matched the local… |
| CVE-2025-32782 | Media (5.3) | 0.31% | — | 15 abr 2025 | Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently uses a GET request triggered by clicking a link sent via email. Some email clients and security… |
| CVE-2025-25202 | Media (6.3) | 0.31% | — | 11 feb 2025 | Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present since AshAuthentication v4.1.0 and who have used the magic link… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.