CVE-2026-107177

CVE-2026-107177 published: Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the default crypto.cipherKey 'sensitiveKey'. Attackers who can read Redis can decr...

View full NVD advisory → ← Back to CVE watch