CVE-2026-53776
Critical · CVSS 9.1Perry — JWT token expiration bypass (CWE-613: Insufficient Session Expiration)
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-613
Description
Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification path. Attackers in possession of a previously issued bearer token can present expired tokens to any jwt.verify() call and retain authenticated access indefinitely, bypassing force-expired sessions such as user logout or administrative revocation.
Search profile — drives PoC discovery
Symbols validate_expverify_decodejwt.verifyvalidate_exp = falsebearer tokenstdlib JWT verification
Keywords CVE-2026-53776Perry JWTPerry PerryTSJWT expiration bypassvalidate_exp falseverify_decode helperjwt.verify bypasstoken revocation bypassexpired bearer tokenGHSA-5324-c68v-8w62Perry before 0.5.1166
Versions: before 0.5.1166
References
Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z