CVE-2026-86522: Log injection via an unescaped password reset identity in AshAuthentication
Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or control characters.
AshAuthentication.Strategy.Password.RequestPasswordReset.run/3 interpolates the identity argument, the email or username taken straight from the reset request, into its Logger.warning/1 heredocs without escaping, truncating or type-restricting it. The resource logged beside it is passed through inspect/1, which would have neutralized the value. A newline in the identity therefore ends the log record, and everything after it is written as a line of its own, so an attacker chooses the severity tag and the content of entries that appear to have come from the application.
This issue affects ashauthentication: from 4.2.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ash_authenticationto a version that resolves this vulnerability.Fixed in 4.15.0 - Upgrade
Upgrade
ash_authenticationto a version that resolves this vulnerability.Fixed in 5.0.0-rc.14
Event History
Frequently Asked Questions
Which releases require remediation?
Affected releases are ash_authentication 4.2.0 through versions before 4.15.0, and 5.0.0-rc.0 through versions before 5.0.0-rc.14. Versions 4.15.0 and 5.0.0-rc.14 are outside the stated affected ranges.
Does exploitation require an authenticated account?
No. An unauthenticated attacker can submit a password reset identity containing newline or control characters.
What application path must be reachable for exploitation?
The attacker-controlled identity must reach the password-reset request flow handled by AshAuthentication.Strategy.Password.RequestPasswordReset.run/3. The vulnerable logging occurs when that identity is interpolated into a Logger.warning/1 message.
What can an attacker change in the logs?
A newline can terminate the original log record and cause subsequent attacker-controlled text to be written as its own line. This allows forged entries with attacker-chosen severity tags and content that can appear application-generated.