team-alembic
ash authentication
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2026-86688 | 17 Sep 2026 | ash authentication: 0.2.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, a939dde9b917c072cdf10c4b0913a9886a4b0231 < * | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-76949 | 17 Sep 2026 | ash authentication: 4.10.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, 3d3de314692558d06ec13945f857f00514e95a8c < * | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-91039 | 17 Sep 2026 | ash authentication: 5.0.0-rc.10 < 5.0.0-rc.14, 64530644f9b37ebb76ca14aeb83a77597a0034b7 < 73ad16e452670bbf843550a13361bd41e72ad964 | Upgrading is not sufficient on its own, for two reasons.; Namespacing changes the value the identity lookup keys on, so UserIdentity rows written before the fix, all holding the bare strategy name, no longer match. Each row's strategy must be relinked in place to "<name>/<connection_id>". Deleting the rows does not work: the block is the account match that follows, refused under the default on_untrusted_email_match :reject whether the row exists or not, and deleting also discards the stored refresh token. Where a deployment has one connection the mapping is unambiguous and the update is mechanical, but it must run in the same deployment as the upgrade and before users sign in, or a newly written namespaced row can collide with a surviving bare row on the (uid, strategy) index.; The fix also cannot separate accounts already merged, and the merge is not detectable from the database, because a collision never produced two rows to compare: the second user's identity was never created and the surviving row looks legitimate. Deployments running more than one connection must audit out of band, by exporting each connection's set of sub values from its identity provider and intersecting them. Any sub present in more than one set identifies an account that may have been merged. | Update reference ↗ |
| CVE-2026-88952 | 17 Sep 2026 | ash authentication: 4.14.0 < 4.15.0, 5.0.0-rc.10 < 5.0.0-rc.14, 64530644f9b37ebb76ca14aeb83a77597a0034b7 < *, 42edcd8ebb13fafbb168f12591d7518ce0611fec < * | Upgrading prevents new links but does not unpick existing ones. An account already linked through this path stays linked, and a victim's email may already have been rewritten to the attacker's address.; Operators whose register action or sign-in action matched on anything other than the email should review their UserIdentity rows for links whose provider email does not match the linked account's email, and check affected accounts for a rewritten email address. | Update reference ↗ |
| CVE-2026-85500 | 17 Sep 2026 | ash authentication: 4.3.8 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, 7d37bc6e4df6697b5813d2f373f0fdb08f813f98 < * | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-86533 | 17 Sep 2026 | ash authentication: 4.9.1 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, fcaeb73f76f8f2e9aef8bf637690d2a20dd97596 < *; ash authentication phoenix: 2.10.0 < 2.17.4, 3.0.0-rc.0 < 3.0.0-rc.11, a3253fb4fc7145aeb403537af1c24d3a8d51ffb1 < *, 0135217e34e621dac79ae3d9559aeee49304b0aa < * | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-80218 | 17 Sep 2026 | ash authentication: 3.10.5 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, eca8cadea0f1595ed2c10a0c177b1da9aa9e5269 < * | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-78223 | 17 Sep 2026 | ash authentication: 0.2.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, a939dde9b917c072cdf10c4b0913a9886a4b0231 < * | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-86522 | 17 Sep 2026 | ash authentication: 4.2.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, 3954f277929712755aef57a4a3a821688f121316 < * | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-81637 | 17 Sep 2026 | ash authentication: 0.6.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, c5f589058e04239263f50a1430eb17ea6d5dd1a2 < * | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-82761 | 17 Sep 2026 | ash authentication: 3.9.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, cf3d227ef25912cf1b0c5fa80f20001f5c46a102 < * | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-82685 | 17 Sep 2026 | ash authentication: 0.5.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, 1d4bb00617aecae85c33f2ff5bc7e094c6449a6e < * | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-82760 | 17 Sep 2026 | ash authentication: 4.8.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, f3a53f480088419788d5c3934af3131fa9066773 < * | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-82759 | 17 Sep 2026 | ash authentication: 4.12.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.14, 255cfc9c0e511b7e0de39f8b3d676ae994fae06c < * | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-82723 | 17 Sep 2026 | ash authentication: 4.12.0 < 4.15.0, 5.0.0-rc.0 < 5.0.0-rc.2, 255cfc9c0e511b7e0de39f8b3d676ae994fae06c < * | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-65633 | 25 Aug 2026 | 3.10.5 < 4.14.2; 5.0.0-rc.0 < 5.0.0-rc.13; eca8cadea0f1595ed2c10a0c177b1da9aa9e5269 < * | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-66882 | 25 Aug 2026 | 4.8.0 < 4.14.2; 5.0.0-rc.0 < 5.0.0-rc.13; fe0b4558dbe852fee5d81a460a8355577618a8c8 < * | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-49757 | 15 Jun 2026 | 0.1.0 < 4.14.0; 5.0.0-rc.0 < 5.0.0-rc.10; c5f589058e04239263f50a1430eb17ea6d5dd1a2 < * | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-32782 | 15 Apr 2025 | < 4.7.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-25202 | 11 Feb 2025 | >= 4.1.0, < 4.4.9 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.