
That's the JWT algorithm restriction (CVE-2026-57997): when plugin::users-permissions.jwt.algorithm isn't set explicitly, HS384 and HS512 tokens are accepted alongside HS256. Worth being precise about the precondition, since the CVE title reads scarier than the scenario: minting a token that Strapi accepts still requires the jwtSecret. An attacker positioned to exploit the algorithm gap already holds the signing key at which point they can mint valid HS256 tokens anyway. It's a hardening gap rather than an authentication bypass. Pinning the algorithm explicitly in your users-permissions config closes it, and current v5 releases include the fix. If you find something in this area, security@strapi.io or a GitHub advisory on the main repo gets it to us directly.
Post summary
The post discloses CVE‑2026‑57997 as an algorithm restriction in Strapi’s JWT handling, explains its technical details, and highlights that the issue is mitigated by pinning the algorithm in configuration and that newer releases include the fix.




