Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-77130

Опубликовано: 25 авг. 2026
Источник: nvd
EPSS Низкий

Описание

The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate with an expired token. Exploitation requires the attacker to already be in control of the SYSSY project's API key.

EPSS

Процентиль: 11%
0.00207
Низкий

Дефекты

CWE-613

Связанные уязвимости

github
28 дней назад

The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate with an expired token. Exploitation requires the attacker to already be in control of the SYSSY project's API key.

EPSS

Процентиль: 11%
0.00207
Низкий

Дефекты

CWE-613