CVE-2026-82726
Received Received - Intake

Permissive Regex in AshPhoenix Allows Tenant Selection

Vulnerability report for CVE-2026-82726, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: EEF

Description

Permissive Regular Expression vulnerability in ash-project ash_phoenix lets a remote client select the tenant an Ash application uses, or degrade the request, by sending a crafted Host header. AshPhoenix.Helpers.get_subdomain/2 stripped the root domain with String.replace(host, ~r/.?#{root_host}/, ""). The root host was interpolated raw, so each . became a wildcard and any metacharacter a pattern, and the replace was global and unanchored, so a match was removed from anywhere in the string. With root_host example.com, Host: foo.exampleXcom.attacker.net returned the tenant foo.attacker.net. A metacharacter-bearing or nil root host degraded the pattern or raised on every request. The comparison was also case-sensitive, so TENANT.EXAMPLE.COM and EXAMPLE.COM slipped past the root-host allowlist. conn.host comes from the client Host header. The fix matches the root host case-insensitively and only as an exact trailing suffix. This issue affects ash_phoenix: from 2.1.26 before 2.3.25.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ash-project ash_phoenix From 2.1.26 (inc) to 2.3.25 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-625 The product uses a regular expression that does not sufficiently restrict the set of allowed values.
CWE-178 The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a permissive regular expression issue in the AshPhoenix library's get_subdomain function. It allows a remote attacker to manipulate tenant selection or degrade requests by sending a crafted Host header. The function incorrectly used an unanchored, global regex to strip the root domain, treating dots as wildcards and metacharacters as patterns. This enabled attackers to bypass tenant isolation or cause errors by injecting malicious subdomains.

Detection Guidance

To detect this vulnerability, inspect your AshPhoenix application logs for malformed Host headers or tenant selection errors. Check if requests with unusual Host headers (e.g., containing regex metacharacters or case mismatches) trigger unexpected tenant assignments or errors. Review the application's subdomain-based multitenancy logic for improper tenant isolation.

Impact Analysis

An attacker could exploit this to select unintended tenants, causing data leakage or misconfiguration. They might also degrade system performance or crash it by triggering regex errors or heavy backtracking. Any application using subdomain-based multitenancy via AshPhoenix is affected.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA by allowing unauthorized tenant access or data exposure. Crafted Host headers may bypass tenant isolation, enabling attackers to access or manipulate data belonging to other tenants. This undermines data segregation requirements in both regulations.

Mitigation Strategies

Upgrade AshPhoenix to version 2.3.25 or later immediately. If upgrading is not possible, implement strict input validation for Host headers by replacing the vulnerable get_subdomain function with a case-insensitive exact suffix match (e.g., String.ends_with?/2). Temporarily disable subdomain-based tenant selection if mitigation is delayed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82726. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart