CVE-2026-107177: high-severity vulnerability in ExpressGateway express-gateway
Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens
Published
18Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.4
exploitation probability
—
observed exploitation
nono source reports it
Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the default crypto.cipherKey 'sensitiveKey'. Attackers who can read Redis can decrypt tokenEncrypted values and combine them with stored token IDs to obtain valid bearer tokens for any user.
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
ExpressGateway · express-gatewayRelated CVEs — ExpressGateway express-gateway
In the same product, most dangerous first.
CVE-2025-9096MEDIUMExpressGateway express-gateway REST Endpoint apps.js cross site scriptingEPSS 0.3%CVE-2025-9095MEDIUMExpressGateway express-gateway REST Endpoint users.js cross site scriptingEPSS 0.3%CVE-2026-107162HIGHExpress Gateway through 1.16.11 OAuth 2.0 Refresh Token Validation BypassEPSS —
References
https://github.com/ExpressGateway/express-gatewayhttps://github.com/ExpressGateway/express-gateway/blob/45612814d12f65889ef3bdf80b2ed7ab9b557736/lib/config/system.config.yml#L15-L22https://github.com/ExpressGateway/express-gateway/blob/45612814d12f65889ef3bdf80b2ed7ab9b557736/lib/services/utils.js#L18-L28https://github.com/ExpressGateway/express-gateway/issues/1078https://www.vulncheck.com/advisories/express-gateway-through-1.16.11-hardcoded-default-cipherkey-exposes-oauth-tokens