Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the default crypto.cipherKey 'sensitiveKey'. Attackers who can read Redis can decrypt tokenEncrypted values and combine them with stored token IDs to obtain valid bearer tokens for any user. | |
| Title | Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens | |
| First Time appeared |
Express-gateway
Express-gateway express-gateway Docker Image |
|
| Weaknesses | CWE-1394 | |
| CPEs | cpe:2.3:a:express-gateway:express-gateway_docker_image:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Express-gateway
Express-gateway express-gateway Docker Image |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-07T12:48:19.043Z
Reserved: 2026-10-07T12:40:26.059Z
Link: CVE-2026-107177
No data.
Status : Received
Published: 2026-10-07T13:17:20.827
Modified: 2026-10-07T13:17:20.827
Link: CVE-2026-107177
No data.
OpenCVE Enrichment
No data.
-
CWE-1394
Use of Default Cryptographic Key