Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 07 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Express-gateway express-gateway
|
|
| Vendors & Products |
Express-gateway express-gateway
|
Wed, 07 Oct 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the default crypto.cipherKey 'sensitiveKey'. Attackers who can read Redis can decrypt tokenEncrypted values and combine them with stored token IDs to obtain valid bearer tokens for any user. | |
| Title | Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens | |
| First Time appeared |
Express-gateway
Express-gateway express-gateway Docker Image |
|
| Weaknesses | CWE-1394 | |
| CPEs | cpe:2.3:a:express-gateway:express-gateway_docker_image:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Express-gateway
Express-gateway express-gateway Docker Image |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-07T12:48:19.043Z
Reserved: 2026-10-07T12:40:26.059Z
Link: CVE-2026-107177
No data.
Status : Awaiting Analysis
Published: 2026-10-07T13:17:20.827
Modified: 2026-10-07T16:02:27.613
Link: CVE-2026-107177
No data.
OpenCVE Enrichment
Updated: 2026-10-07T15:00:07Z