Known Vulnerabilities for Ash Authentication Oauth2 Server by Ash-project
Listed below are 5 of the newest known vulnerabilities associated with "Ash Authentication Oauth2 Server" by "Ash-project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-81029 json | OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServl... | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-70636 json | Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAu... | Not Provided | 2026-08-06 | 2026-08-14 |
| CVE-2026-69250 json | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token ref... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-65594 json | n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was intr... | Not Provided | 2026-07-22 | 2026-07-23 |
| CVE-2026-42604 json | Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= ... | Not Provided | 2026-06-12 | 2026-06-15 |