PatchSiren

ExpressGateway CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ExpressGateway CVE published 2026-10-07

CVE-2026-107177

CVE-2026-107177 debrief: Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability allowing attackers with datastore access to decrypt stored OAuth 2.0 token secrets. This vulnerability, with a CVSS score of 7.4 and classified as HIGH severity, enables attackers to combine decrypted tokenEncrypted values with stored token IDs to obtain valid bearer tokens for any user. Defenders [truncated]