CVE-2026-107177

Source
https://cve.org/CVERecord?id=CVE-2026-107177
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107177.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107177
Published
2026-10-07T12:48:19Z
Modified
2026-10-09T02:49:20Z
Severity
  • 7.4 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens
Details

Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the default crypto.cipherKey 'sensitiveKey'. Attackers who can read Redis can decrypt tokenEncrypted values and combine them with stored token IDs to obtain valid bearer tokens for any user.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-1394"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107177.json"
}
References

Affected packages

Git / github.com/expressgateway/express-gateway

Affected ranges

Type
GIT
Repo
https://github.com/expressgateway/express-gateway
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.16.11"
        },
        {
            "fixed": "1.16.11"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

0.*
0.1.0
v0.*
v0.0.2
v0.10.0
v0.11.0
v0.9.0
v1.*
v1.0.0
v1.0.1
v1.0.2
v1.1.0
v1.1.1
v1.10.0
v1.10.1
v1.10.2
v1.11.0
v1.12.0
v1.12.1
v1.13.0
v1.14.0
v1.15.0
v1.16
v1.16.0
v1.16.1
v1.16.10
v1.16.2
v1.16.3
v1.16.6
v1.16.7
v1.16.8
v1.16.9
v1.2.0
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.7.0
v1.7.2
v1.7.3
v1.8.0
v1.8.1
v1.8.2
v1.9.0
v1.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107177.json"