AshPhoenix.Helpers.get_subdomain/2 stripped the root domain with String.replace(host, ~r/.?#{root_host}/, ""). The root host was interpolated raw, so each . became a wildcard and any metacharacter a pattern, and the replace was global and unanchored, so a match was removed from anywhere in the string. With root_host example.com, Host: foo.exampleXcom.attacker.net returned the tenant foo.attacker.net. A metacharacter-bearing or nil root host degraded the pattern or raised on every request. The comparison was also case-sensitive, so TENANT.EXAMPLE.COM and EXAMPLE.COM slipped past the root-host allowlist. conn.host comes from the client Host header. The fix matches the root host case-insensitively and only as an exact trailing suffix.
This issue affects ash_phoenix: from 2.1.26 before 2.3.25.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Permissive Regular Expression vulnerability in ash-project ash_phoenix lets a remote client select the tenant an Ash application uses, or degrade the request, by sending a crafted Host header. AshPhoenix.Helpers.get_subdomain/2 stripped the root domain with String.replace(host, ~r/.?#{root_host}/, ""). The root host was interpolated raw, so each . became a wildcard and any metacharacter a pattern, and the replace was global and unanchored, so a match was removed from anywhere in the string. With root_host example.com, Host: foo.exampleXcom.attacker.net returned the tenant foo.attacker.net. A metacharacter-bearing or nil root host degraded the pattern or raised on every request. The comparison was also case-sensitive, so TENANT.EXAMPLE.COM and EXAMPLE.COM slipped past the root-host allowlist. conn.host comes from the client Host header. The fix matches the root host case-insensitively and only as an exact trailing suffix. This issue affects ash_phoenix: from 2.1.26 before 2.3.25. | |
| Title | AshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary tenant | |
| First Time appeared |
Ash-project
Ash-project ash Phoenix |
|
| Weaknesses | CWE-178 CWE-625 |
|
| CPEs | cpe:2.3:a:ash-project:ash_phoenix:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ash-project
Ash-project ash Phoenix |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-08-31T03:05:38.612Z
Reserved: 2026-08-31T00:59:08.960Z
Link: CVE-2026-82726
No data.
Status : Received
Published: 2026-08-31T04:17:29.357
Modified: 2026-08-31T04:17:29.357
Link: CVE-2026-82726
No data.
OpenCVE Enrichment
Updated: 2026-08-31T05:00:04Z