CVE-2026-107177: fallo de gravedad alta en ExpressGateway express-gateway
Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens
Publicada el
18Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.4
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the default crypto.cipherKey 'sensitiveKey'. Attackers who can read Redis can decrypt tokenEncrypted values and combine them with stored token IDs to obtain valid bearer tokens for any user.
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
ExpressGateway · express-gatewayCVEs relacionadas — ExpressGateway express-gateway
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-9096MEDIUMExpressGateway express-gateway REST Endpoint apps.js cross site scriptingEPSS 0.3%CVE-2025-9095MEDIUMExpressGateway express-gateway REST Endpoint users.js cross site scriptingEPSS 0.3%CVE-2026-107162HIGHExpress Gateway through 1.16.11 OAuth 2.0 Refresh Token Validation BypassEPSS —
Referencias
https://github.com/ExpressGateway/express-gatewayhttps://github.com/ExpressGateway/express-gateway/blob/45612814d12f65889ef3bdf80b2ed7ab9b557736/lib/config/system.config.yml#L15-L22https://github.com/ExpressGateway/express-gateway/blob/45612814d12f65889ef3bdf80b2ed7ab9b557736/lib/services/utils.js#L18-L28https://github.com/ExpressGateway/express-gateway/issues/1078https://www.vulncheck.com/advisories/express-gateway-through-1.16.11-hardcoded-default-cipherkey-exposes-oauth-tokens