CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-53776

Critical · CVSS 9.1

Perry — JWT token expiration bypass (CWE-613: Insufficient Session Expiration)

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-613

Description

Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification path. Attackers in possession of a previously issued bearer token can present expired tokens to any jwt.verify() call and retain authenticated access indefinitely, bypassing force-expired sessions such as user logout or administrative revocation.

Search profile — drives PoC discovery

Symbols validate_expverify_decodejwt.verifyvalidate_exp = falsebearer tokenstdlib JWT verification
Keywords CVE-2026-53776Perry JWTPerry PerryTSJWT expiration bypassvalidate_exp falseverify_decode helperjwt.verify bypasstoken revocation bypassexpired bearer tokenGHSA-5324-c68v-8w62Perry before 0.5.1166
Versions: before 0.5.1166

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z