Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY20 SECURITY RECORDS

team-alembic

ash authentication

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-86688 17 Sep 2026 ash authentication: 0.2.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, a939dde9b917c072cdf10c4b0913a9886a4b0231 < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-76949 17 Sep 2026 ash authentication: 4.10.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, 3d3de314692558d06ec13945f857f00514e95a8c < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-91039 17 Sep 2026 ash authentication: 5.0.0-rc.10 < 5.0.0-rc.14, 64530644f9b37ebb76ca14aeb83a77597a0034b7 < 73ad16e452670bbf843550a13361bd41e72ad964 Upgrading is not sufficient on its own, for two reasons.; Namespacing changes the value the identity lookup keys on, so UserIdentity rows written before the fix, all holding the bare strategy name, no longer match. Each row's strategy must be relinked in place to "<name>/<connection_id>". Deleting the rows does not work: the block is the account match that follows, refused under the default on_untrusted_email_match :reject whether the row exists or not, and deleting also discards the stored refresh token. Where a deployment has one connection the mapping is unambiguous and the update is mechanical, but it must run in the same deployment as the upgrade and before users sign in, or a newly written namespaced row can collide with a surviving bare row on the (uid, strategy) index.; The fix also cannot separate accounts already merged, and the merge is not detectable from the database, because a collision never produced two rows to compare: the second user's identity was never created and the surviving row looks legitimate. Deployments running more than one connection must audit out of band, by exporting each connection's set of sub values from its identity provider and intersecting them. Any sub present in more than one set identifies an account that may have been merged. Update reference ↗
CVE-2026-88952 17 Sep 2026 ash authentication: 4.14.0 < 4.15.0, 5.0.0-rc.10 < 5.0.0-rc.14, 64530644f9b37ebb76ca14aeb83a77597a0034b7 < *, 42edcd8ebb13fafbb168f12591d7518ce0611fec < * Upgrading prevents new links but does not unpick existing ones. An account already linked through this path stays linked, and a victim's email may already have been rewritten to the attacker's address.; Operators whose register action or sign-in action matched on anything other than the email should review their UserIdentity rows for links whose provider email does not match the linked account's email, and check affected accounts for a rewritten email address. Update reference ↗
CVE-2026-85500 17 Sep 2026 ash authentication: 4.3.8 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, 7d37bc6e4df6697b5813d2f373f0fdb08f813f98 < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-86533 17 Sep 2026 ash authentication: 4.9.1 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, fcaeb73f76f8f2e9aef8bf637690d2a20dd97596 < *; ash authentication phoenix: 2.10.0 < 2.17.4, 3.0.0-rc.0 < 3.0.0-rc.11, a3253fb4fc7145aeb403537af1c24d3a8d51ffb1 < *, 0135217e34e621dac79ae3d9559aeee49304b0aa < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-80218 17 Sep 2026 ash authentication: 3.10.5 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, eca8cadea0f1595ed2c10a0c177b1da9aa9e5269 < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-78223 17 Sep 2026 ash authentication: 0.2.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, a939dde9b917c072cdf10c4b0913a9886a4b0231 < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-86522 17 Sep 2026 ash authentication: 4.2.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, 3954f277929712755aef57a4a3a821688f121316 < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-81637 17 Sep 2026 ash authentication: 0.6.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, c5f589058e04239263f50a1430eb17ea6d5dd1a2 < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-82761 17 Sep 2026 ash authentication: 3.9.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, cf3d227ef25912cf1b0c5fa80f20001f5c46a102 < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-82685 17 Sep 2026 ash authentication: 0.5.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, 1d4bb00617aecae85c33f2ff5bc7e094c6449a6e < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-82760 17 Sep 2026 ash authentication: 4.8.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, f3a53f480088419788d5c3934af3131fa9066773 < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-82759 17 Sep 2026 ash authentication: 4.12.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, 255cfc9c0e511b7e0de39f8b3d676ae994fae06c < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-82723 17 Sep 2026 ash authentication: 4.12.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.2, 255cfc9c0e511b7e0de39f8b3d676ae994fae06c < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-65633 25 Aug 2026 3.10.5 < 4.14.2; 5.0.0-rc.0 < 5.0.0-rc.13; eca8cadea0f1595ed2c10a0c177b1da9aa9e5269 < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-66882 25 Aug 2026 4.8.0 < 4.14.2; 5.0.0-rc.0 < 5.0.0-rc.13; fe0b4558dbe852fee5d81a460a8355577618a8c8 < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-49757 15 Jun 2026 0.1.0 < 4.14.0; 5.0.0-rc.0 < 5.0.0-rc.10; c5f589058e04239263f50a1430eb17ea6d5dd1a2 < * No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-32782 15 Apr 2025 < 4.7.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-25202 11 Feb 2025 >= 4.1.0, < 4.4.9 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.