CVE-2026-82757: ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF

Published Sep 7, 2026
·
Updated

Server-Side Request Forgery (SSRF) vulnerability in ash-project ashauthenticationoauth2server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses.

publicip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy for CIMD metadata fetches. It classified several address forms as publicly routable that are not: IPv4-compatible ::/96 (for example ::127.0.0.1), SIIT IPv4-translated ::ffff:0:0:0/96, and deprecated site-local fec0::/10. A returned AAAA record in one of these ranges passed the policy, so a fetch pinned to that address reached space the policy was meant to block.

This issue affects ashauthenticationoauth2server: from 0.3.0 before 0.3.1.

Affected Software

1 affected component
ash-project/ash_authentication_oauth2_server>0.3.0<0.3.1

Event History

Sep 7, 2026
CVE Published
via MITRE·10:31 PM
Data Sourced
via MITRE·10:31 PM
DescriptionWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments using ash_authentication_oauth2_server versions 0.3.0 before 0.3.1 are affected if an attacker can control a client metadata URL and the DNS resolution for that URL.

2

What does an attacker need to do to exploit it?

The attacker needs to cause a CIMD metadata fetch for a host they control and return an AAAA record using an address form incorrectly treated as public, such as IPv4-compatible IPv6, SIIT IPv4-translated IPv6, or deprecated site-local IPv6. The server can then connect to internal or loopback address space that the outbound policy was intended to block.

3

How can I tell whether my deployment is affected?

Check the installed ash_authentication_oauth2_server version. Versions from 0.3.0 up to, but not including, 0.3.1 are affected; version 0.3.1 is outside the stated affected range.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203