CVE-2026-45091Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's literal TOTP secret in the JWS payload of every minted unseal token. JWS payload is base64-encoded JSON, NOT encrypted. Any party who could observe a minted token (CI build logs, container env dumps, kubectl describe pod, Sentry/Rollbar stack traces, log aggregators) could decode the payload and extract the TOTP secret in plaintext. This vulnerability is fixed in 0.1.0-alpha.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-522

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-12: 1Technical Details · 2026-05-12: 105-12
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - sealed-env TOTP Secret Exposure in Unseal Token (CVE-2026-45091) In sealed-env enterprise mode, versions prior to 0.1.0-alpha.4 embed the operator's literal TOTP secret directly in the base64-encoded JWS payload of minted unseal tokens. Any observer who can access a token (e.g., CI logs, container dumps, or error trackers) can extract the secret in plaintext. This breaks the second-factor protection: an attacker with the master key and one leaked token can mint unlimited new unseal tokens indefinitely. 👉Affected: sealed-env < 0.1.0-alpha.4 (Maven + npm)

    Post summary

    The post announces a new critical vulnerability (CVE-2026-45091) affecting sealed‑env prior to 0.1.0‑alpha.4, detailing how the TOTP secret is exposed in unseal tokens without providing PoC or exploit code.

    0002084
    187 followersView on X

Explore more