Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the default crypto.cipherKey 'sensitiveKey'. Attackers who can read Redis can decrypt tokenEncrypted values and combine them with stored token IDs to obtain valid bearer tokens for any user.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the default crypto.cipherKey 'sensitiveKey'. Attackers who can read Redis can decrypt tokenEncrypted values and combine them with stored token IDs to obtain valid bearer tokens for any user. | |
| Title | Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens | |
| First Time appeared |
Express-gateway
Express-gateway express-gateway Docker Image |
|
| Weaknesses | CWE-1394 | |
| CPEs | cpe:2.3:a:express-gateway:express-gateway_docker_image:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Express-gateway
Express-gateway express-gateway Docker Image |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-07T12:48:19.043Z
Reserved: 2026-10-07T12:40:26.059Z
Link: CVE-2026-107177
No data.
Status : Received
Published: 2026-10-07T13:17:20.827
Modified: 2026-10-07T13:17:20.827
Link: CVE-2026-107177
No data.
OpenCVE Enrichment
No data.
Weaknesses