Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-57997

Опубликовано: 29 июн. 2026
Источник: nvd
CVSS3: 4.8
CVSS3: 5.4
EPSS Низкий

Описание

Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512 tokens alongside HS256. Attackers possessing the jwtSecret can mint tokens with non-standard HMAC variants to bypass algorithm restrictions and weaken authentication controls.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:strapi:strapi:*:*:*:*:*:node.js:*:*
Версия до 5.7.0 (исключая)

EPSS

Процентиль: 16%
0.00249
Низкий

4.8 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 4.8
github
2 месяца назад

Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512 tokens alongside HS256. Attackers possessing the jwtSecret can mint tokens with non-standard HMAC variants to bypass algorithm restrictions and weaken authentication controls.

EPSS

Процентиль: 16%
0.00249
Низкий

4.8 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-327