VYPR

Ash Authentication Phoenix

by Team Alembic

Source repositories

CVEs (3)

  • CVE-2026-86533CriSep 17, 2026
    risk 0.52cvss —epss 0.01

    Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_presence_for_authentication? disabled…

  • CVE-2026-81632HigSep 17, 2026
    risk 0.40cvss —epss 0.00

    Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its owner. After a successful password…

  • CVE-2025-4754LowJun 17, 2025
    risk 0.08cvss —epss 0.01

    Insufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign-out to remain usable afterwards. The default sign_out/2 that AshAuthentication.Phoenix.Controller injects into an application's auth controller…