πŸ” CVE Alert

CVE-2026-82761

UNKNOWN 0.0

Magic link single-use tokens replayable via TOCTOU race in AshAuthentication

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as the target subject. A magic link configured with single_use_token?, which is the default, is meant to be redeemable exactly once, but nothing serialises the token's validity check against its consumption, so concurrent redemptions of one token all succeed and each yields a full user token. Sign-in verifies the JWT with Jwt.verify/4 and revokes it only afterwards: AshAuthentication.Strategy.MagicLink.SignInPreparation revokes in a Query.after_action callback, and AshAuthentication.Strategy.MagicLink.SignInChange in an after_transaction hook that runs once the sign-in has already committed. AshAuthentication.TokenResource.Actions.revoke/3 writes the revocation as an upsert, so a concurrent duplicate revocation silently succeeds instead of conflicting and no request ever loses the race. This issue affects ash_authentication: from 3.9.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.

CWE CWE-367
Vendor team-alembic
Product ash_authentication
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for team-alembic ash_authentication

Be the first to know when new unknown vulnerabilities affecting team-alembic ash_authentication are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

team-alembic / ash_authentication
3.9.0 < 4.15.0 5.0.0-rc.0 < 5.0.0-rc.14
team-alembic / ash_authentication
cf3d227ef25912cf1b0c5fa80f20001f5c46a102 < *

References

NVD β†— CVE.org β†— EPSS Data β†—
github.com: https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-23gr-vcp4-r27q cna.erlef.org: https://cna.erlef.org/cves/CVE-2026-82761.html osv.dev: https://osv.dev/vulnerability/EEF-CVE-2026-82761 github.com: https://github.com/team-alembic/ash_authentication/commit/cf3d227ef25912cf1b0c5fa80f20001f5c46a102 github.com: https://github.com/team-alembic/ash_authentication/commit/18dfdb36c14aa6a61df8572bce2d5ec36b1d9840 github.com: https://github.com/team-alembic/ash_authentication/commit/9ef6864b8833d3b795427a7b8dc518a4997d41ab

Credits

James Harton πŸ” Peter Ullrich Jonatan MΓ€nnchen / EEF