{"api_version":"v1","generated_at":"2026-10-08T11:00:00+00:00","product":{"cve_count":20,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-team-alembic-ash-authentication-7eaf77f89389","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"ash authentication","next_cursor":null,"observations":[{"affected":"ash authentication: 0.2.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, a939dde9b917c072cdf10c4b0913a9886a4b0231 < *","affected_versions_present":true,"cve_id":"CVE-2026-86688","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86688","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-18T14:31:41.961Z","patch_url":"","primary_source":"","published":"2026-09-17T21:58:00.853Z"},{"affected":"ash authentication: 4.10.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, 3d3de314692558d06ec13945f857f00514e95a8c < *","affected_versions_present":true,"cve_id":"CVE-2026-76949","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76949","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-18T14:31:41.806Z","patch_url":"","primary_source":"","published":"2026-09-17T21:57:50.146Z"},{"affected":"ash authentication: 5.0.0-rc.10 < 5.0.0-rc.14, 64530644f9b37ebb76ca14aeb83a77597a0034b7 < 73ad16e452670bbf843550a13361bd41e72ad964","affected_versions_present":true,"cve_id":"CVE-2026-91039","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91039","fixed":"Upgrading is not sufficient on its own, for two reasons.; Namespacing changes the value the identity lookup keys on, so UserIdentity rows written before the fix, all holding the bare strategy name, no longer match. Each row's strategy must be relinked in place to \"<name>/<connection_id>\". Deleting the rows does not work: the block is the account match that follows, refused under the default on_untrusted_email_match :reject whether the row exists or not, and deleting also discards the stored refresh token. Where a deployment has one connection the mapping is unambiguous and the update is mechanical, but it must run in the same deployment as the upgrade and before users sign in, or a newly written namespaced row can collide with a surviving bare row on the (uid, strategy) index.; The fix also cannot separate accounts already merged, and the merge is not detectable from the database, because a collision never produced two rows to compare: the second user's identity was never created and the surviving row looks legitimate. Deployments running more than one connection must audit out of band, by exporting each connection's set of sub values from its identity provider and intersecting them. Any sub present in more than one set identifies an account that may have been merged.","last_modified":"2026-09-17T19:40:32.068Z","patch_url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-73j9-m294-fvv9","primary_source":"","published":"2026-09-17T15:19:15.994Z"},{"affected":"ash authentication: 4.14.0 < 4.15.0, 5.0.0-rc.10 < 5.0.0-rc.14, 64530644f9b37ebb76ca14aeb83a77597a0034b7 < *, 42edcd8ebb13fafbb168f12591d7518ce0611fec < *","affected_versions_present":true,"cve_id":"CVE-2026-88952","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-88952","fixed":"Upgrading prevents new links but does not unpick existing ones. An account already linked through this path stays linked, and a victim's email may already have been rewritten to the attacker's address.; Operators whose register action or sign-in action matched on anything other than the email should review their UserIdentity rows for links whose provider email does not match the linked account's email, and check affected accounts for a rewritten email address.","last_modified":"2026-09-17T19:32:55.621Z","patch_url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-wc6x-276q-jrf9","primary_source":"","published":"2026-09-17T14:15:19.506Z"},{"affected":"ash authentication: 4.3.8 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, 7d37bc6e4df6697b5813d2f373f0fdb08f813f98 < *","affected_versions_present":true,"cve_id":"CVE-2026-85500","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-85500","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-17T18:12:54.127Z","patch_url":"","primary_source":"","published":"2026-09-17T13:09:43.000Z"},{"affected":"ash authentication: 4.9.1 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, fcaeb73f76f8f2e9aef8bf637690d2a20dd97596 < *; ash authentication phoenix: 2.10.0 < 2.17.4, 3.0.0-rc.0 < 3.0.0-rc.11, a3253fb4fc7145aeb403537af1c24d3a8d51ffb1 < *, 0135217e34e621dac79ae3d9559aeee49304b0aa < *","affected_versions_present":true,"cve_id":"CVE-2026-86533","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86533","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-17T18:17:21.199Z","patch_url":"","primary_source":"","published":"2026-09-17T13:09:37.963Z"},{"affected":"ash authentication: 3.10.5 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, eca8cadea0f1595ed2c10a0c177b1da9aa9e5269 < *","affected_versions_present":true,"cve_id":"CVE-2026-80218","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-80218","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-17T18:28:47.571Z","patch_url":"","primary_source":"","published":"2026-09-17T13:09:25.585Z"},{"affected":"ash authentication: 0.2.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, a939dde9b917c072cdf10c4b0913a9886a4b0231 < *","affected_versions_present":true,"cve_id":"CVE-2026-78223","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-78223","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-17T18:28:20.821Z","patch_url":"","primary_source":"","published":"2026-09-17T13:09:19.591Z"},{"affected":"ash authentication: 4.2.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, 3954f277929712755aef57a4a3a821688f121316 < *","affected_versions_present":true,"cve_id":"CVE-2026-86522","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86522","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-17T18:27:51.681Z","patch_url":"","primary_source":"","published":"2026-09-17T13:09:11.572Z"},{"affected":"ash authentication: 0.6.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, c5f589058e04239263f50a1430eb17ea6d5dd1a2 < *","affected_versions_present":true,"cve_id":"CVE-2026-81637","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-81637","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-17T18:26:58.389Z","patch_url":"","primary_source":"","published":"2026-09-17T13:09:06.571Z"},{"affected":"ash authentication: 3.9.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, cf3d227ef25912cf1b0c5fa80f20001f5c46a102 < *","affected_versions_present":true,"cve_id":"CVE-2026-82761","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82761","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-17T18:26:08.563Z","patch_url":"","primary_source":"","published":"2026-09-17T13:09:01.534Z"},{"affected":"ash authentication: 0.5.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, 1d4bb00617aecae85c33f2ff5bc7e094c6449a6e < *","affected_versions_present":true,"cve_id":"CVE-2026-82685","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82685","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-17T18:23:51.075Z","patch_url":"","primary_source":"","published":"2026-09-17T13:08:56.491Z"},{"affected":"ash authentication: 4.8.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, f3a53f480088419788d5c3934af3131fa9066773 < *","affected_versions_present":true,"cve_id":"CVE-2026-82760","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82760","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-17T18:21:26.238Z","patch_url":"","primary_source":"","published":"2026-09-17T13:08:46.382Z"},{"affected":"ash authentication: 4.12.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, 255cfc9c0e511b7e0de39f8b3d676ae994fae06c < *","affected_versions_present":true,"cve_id":"CVE-2026-82759","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82759","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-17T18:19:18.209Z","patch_url":"","primary_source":"","published":"2026-09-17T13:08:21.929Z"},{"affected":"ash authentication: 4.12.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.2, 255cfc9c0e511b7e0de39f8b3d676ae994fae06c < *","affected_versions_present":true,"cve_id":"CVE-2026-82723","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82723","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-24T20:47:32.536Z","patch_url":"","primary_source":"","published":"2026-09-17T13:08:05.355Z"},{"affected":"3.10.5 < 4.14.2; 5.0.0-rc.0 < 5.0.0-rc.13; eca8cadea0f1595ed2c10a0c177b1da9aa9e5269 < *","affected_versions_present":true,"cve_id":"CVE-2026-65633","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-65633","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-25T19:49:22.437Z","patch_url":"","primary_source":"","published":"2026-08-25T08:03:51.846Z"},{"affected":"4.8.0 < 4.14.2; 5.0.0-rc.0 < 5.0.0-rc.13; fe0b4558dbe852fee5d81a460a8355577618a8c8 < *","affected_versions_present":true,"cve_id":"CVE-2026-66882","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-66882","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-25T19:51:21.332Z","patch_url":"","primary_source":"","published":"2026-08-25T08:03:47.721Z"},{"affected":"0.1.0 < 4.14.0; 5.0.0-rc.0 < 5.0.0-rc.10; c5f589058e04239263f50a1430eb17ea6d5dd1a2 < *","affected_versions_present":true,"cve_id":"CVE-2026-49757","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49757","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-15T14:14:37.882Z","patch_url":"","primary_source":"","published":"2026-06-15T10:07:17.781Z"},{"affected":"< 4.7.0","affected_versions_present":true,"cve_id":"CVE-2025-32782","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32782","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-16T15:36:23.539Z","patch_url":"","primary_source":"","published":"2025-04-15T22:04:41.667Z"},{"affected":">= 4.1.0, < 4.4.9","affected_versions_present":true,"cve_id":"CVE-2025-25202","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-25202","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-12T20:12:08.180Z","patch_url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-qrm9-f75w-hg4c","primary_source":"","published":"2025-02-11T18:28:19.046Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"team-alembic"}}
