CVE-2026-82757: ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
Server-Side Request Forgery (SSRF) vulnerability in ash-project ashauthenticationoauth2server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses.
publicip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy for CIMD metadata fetches. It classified several address forms as publicly routable that are not: IPv4-compatible ::/96 (for example ::127.0.0.1), SIIT IPv4-translated ::ffff:0:0:0/96, and deprecated site-local fec0::/10. A returned AAAA record in one of these ranges passed the policy, so a fetch pinned to that address reached space the policy was meant to block.
This issue affects ashauthenticationoauth2server: from 0.3.0 before 0.3.1.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments using ash_authentication_oauth2_server versions 0.3.0 before 0.3.1 are affected if an attacker can control a client metadata URL and the DNS resolution for that URL.
What does an attacker need to do to exploit it?
The attacker needs to cause a CIMD metadata fetch for a host they control and return an AAAA record using an address form incorrectly treated as public, such as IPv4-compatible IPv6, SIIT IPv4-translated IPv6, or deprecated site-local IPv6. The server can then connect to internal or loopback address space that the outbound policy was intended to block.
How can I tell whether my deployment is affected?
Check the installed ash_authentication_oauth2_server version. Versions from 0.3.0 up to, but not including, 0.3.1 are affected; version 0.3.1 is outside the stated affected range.