team-alembic
Web & CMS Pluginsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting team-alembic.
- CVE-2026-86688Session id is not renewed on authentication in ash_authentication, allowing session fixation
- CVE-2026-76949Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement
- CVE-2026-91039dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover
- CVE-2026-88952OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication
- CVE-2026-85500`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication
- CVE-2026-86533Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix
- CVE-2026-81632Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix
- CVE-2026-80218Sign-in token minted for one resource accepted by another in AshAuthentication
- CVE-2026-78223Token revocation record built from unverified JWT claims in AshAuthentication
- CVE-2026-86522Log injection via an unescaped password reset identity in AshAuthentication
- CVE-2026-81637Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication
- CVE-2026-82761Magic link single-use tokens replayable via TOCTOU race in AshAuthentication
- CVE-2026-82685Confirmation token accepted on any record in AshAuthentication
- CVE-2026-82760Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in
- CVE-2026-82759Reversible IP address pseudonymisation in AshAuthentication audit log hash mode