oauth2_server_protocol_routes/1 in AshAuthentication.Phoenix.Oauth2Server.Router forwards the same ProtocolRouter at both the /oauth prefix and the /.well-known prefix. Phoenix forward strips the matched prefix before dispatch, so the full route table answers under both mounts, and POST /register, POST /token, and POST /revoke are reachable as /.well-known/register, /.well-known/token, and /.well-known/revoke. Edge controls such as WAF rules, rate limits, or authentication exemptions written against the /oauth paths, or that allow-list /.well-known as unauthenticated, do not apply to the alias.
This issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix. oauth2_server_protocol_routes/1 in AshAuthentication.Phoenix.Oauth2Server.Router forwards the same ProtocolRouter at both the /oauth prefix and the /.well-known prefix. Phoenix forward strips the matched prefix before dispatch, so the full route table answers under both mounts, and POST /register, POST /token, and POST /revoke are reachable as /.well-known/register, /.well-known/token, and /.well-known/revoke. Edge controls such as WAF rules, rate limits, or authentication exemptions written against the /oauth paths, or that allow-list /.well-known as unauthenticated, do not apply to the alias. This issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1. | |
| Title | ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls | |
| First Time appeared |
Ash-project
Ash-project ash Authentication Oauth2 Server |
|
| Weaknesses | CWE-424 | |
| CPEs | cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ash-project
Ash-project ash Authentication Oauth2 Server |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-09-08T14:41:45.077Z
Reserved: 2026-08-31T01:00:10.817Z
Link: CVE-2026-82754
Updated: 2026-09-08T14:41:40.566Z
Status : Deferred
Published: 2026-09-07T23:16:52.403
Modified: 2026-09-08T15:18:50.320
Link: CVE-2026-82754
No data.
OpenCVE Enrichment
Updated: 2026-09-08T01:00:11Z
-
CWE-424
Improper Protection of Alternate Path