CVE-2026-57997Disclosure(strapi / strapi)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch strapi strapi systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512 tokens alongside HS256. Attackers possessing the jwtSecret can mint tokens with non-standard HMAC variants to bypass algorithm restrictions and weaken authentication controls.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-327

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • strapi

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-06-29); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
strapi

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-06-29: 2Mentions · 2026-06-30: 2Mentions · 2026-07-31: 1Patch / Workaround · 2026-07-31: 1Technical Details · 2026-06-29: 2Technical Details · 2026-06-30: 1Technical Details · 2026-07-31: 106-2906-3007-31
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-292
Disclosure2
2026-06-302
General2
2026-07-311
Patch1
Full discourse5 posts
  • Paul Bratslavsky | formerly coding after thirty@codingthirty
    Patch

    That's the JWT algorithm restriction (CVE-2026-57997): when plugin::users-permissions.jwt.algorithm isn't set explicitly, HS384 and HS512 tokens are accepted alongside HS256. Worth being precise about the precondition, since the CVE title reads scarier than the scenario: minting a token that Strapi accepts still requires the jwtSecret. An attacker positioned to exploit the algorithm gap already holds the signing key at which point they can mint valid HS256 tokens anyway. It's a hardening gap rather than an authentication bypass. Pinning the algorithm explicitly in your users-permissions config closes it, and current v5 releases include the fix. If you find something in this area, security@strapi.io or a GitHub advisory on the main repo gets it to us directly.

    Post summary

    The post discloses CVE‑2026‑57997 as an algorithm restriction in Strapi’s JWT handling, explains its technical details, and highlights that the issue is mitigated by pinning the algorithm in configuration and that newer releases include the fix.

    0000047
    1.4K followersView on X
  • VulDB 🛡@vuldb
    General

    Some increased actor activities are shown targeting Strapi (CVE-2026-57997) https://vuldb.com/vuln/374734/cti

    Post summary

    The post hints at increased actor interest in Strapi CVE‑2026‑57997, but provides no concrete evidence of exploitation, PoC, or mitigation steps.

    00000107
    2.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-57997 JWT Algorithm Restriction Bypass in Strapi Users-Permissions Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-57997

    Post summary

    A new CVE (CVE-2026-57997) for a JWT algorithm restriction bypass in Strapi is announced, but the source text offers no further details on exploits, patches, or active attacks.

    00000111
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-57997 Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS3… https://www.cve.org/CVERecord?id=CVE-2026-57997 ----- Traducción: CVE-2026-57997 Str… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-57997, noting that Strapi’s users‑permissions plugin does not enforce JWT algorithm restrictions, specifically permitting HS3 when the setting is unset.

    0000036
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-57997 Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS3… https://www.cve.org/CVERecord?id=CVE-2026-57997

    Post summary

    The CVE highlights a JWT algorithm restriction flaw in Strapi's users-permissions plugin, enabling usage of HS3 algorithms without configuration, but provides no details on exploitation, patches, or active attacks.

    00000646
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstrapistrapi-node.js-

Explore more