Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 16 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Perryts
Perryts perry |
|
| Vendors & Products |
Perryts
Perryts perry |
Tue, 16 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification path. Attackers in possession of a previously issued bearer token can present expired tokens to any jwt.verify() call and retain authenticated access indefinitely, bypassing force-expired sessions such as user logout or administrative revocation. | |
| Title | Perry < 0.5.1166 JWT Expiration Bypass via verify_decode | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-16T17:10:04.656Z
Reserved: 2026-06-10T20:14:32.825Z
Link: CVE-2026-53776
Updated: 2026-06-16T17:09:31.535Z
Status : Deferred
Published: 2026-06-16T17:16:42.620
Modified: 2026-06-16T17:36:59.703
Link: CVE-2026-53776
No data.
OpenCVE Enrichment
Updated: 2026-06-17T21:45:02Z