Cryptographic Key Vulnerability in Express Gateway by Express Gateway
CVE-2026-107177
7.4HIGH
What is CVE-2026-107177?
Express Gateway versions up to 1.16.11 are susceptible to a vulnerability caused by a hardcoded cryptographic key, which can be exploited by attackers possessing datastore access. This flaw enables unauthorized users to decrypt stored OAuth 2.0 token secrets using the default cipherKey labeled 'sensitiveKey.' If an attacker can access the Redis store, they may retrieve encrypted token values and combine them with known token IDs to generate valid bearer tokens for any user, leading to potential unauthorized access.
Affected Version(s)
express-gateway 0 <= 1.16.11
