Cryptographic Key Vulnerability in Express Gateway by Express Gateway
CVE-2026-107177

7.4HIGH

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-107177?

Express Gateway versions up to 1.16.11 are susceptible to a vulnerability caused by a hardcoded cryptographic key, which can be exploited by attackers possessing datastore access. This flaw enables unauthorized users to decrypt stored OAuth 2.0 token secrets using the default cipherKey labeled 'sensitiveKey.' If an attacker can access the Redis store, they may retrieve encrypted token values and combine them with known token IDs to generate valid bearer tokens for any user, leading to potential unauthorized access.

Affected Version(s)

express-gateway 0 <= 1.16.11

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MD Mahmidul Hasan
.