Junglewise Threat Intelligence

CVE-2026-53776: Perry JWT expiration bypass in verify_decode helper

CVE-2026-53776 · Severity: critical · CVSS 9.1 · Published 2026-06-16

Executive brief

Perry, a runtime environment designed for Node.js compatibility, contains a flaw in how it handles security tokens (JWTs). The system fails to check if a login token has expired, meaning an attacker who obtains an old token can use it to access a user's account indefinitely. This allows unauthorized access even after a user has logged out or an administrator has tried to revoke their session.

Technical details

A vulnerability in Perry's standard library JWT implementation (specifically the verify_decode helper) causes the 'exp' (expiration) claim to be ignored during token validation. The root cause is the hardcoded setting of 'validate_exp = false' in the underlying Rust jsonwebtoken crate integration, which deviates from the expected Node.js 'jsonwebtoken' behavior where expiration is enforced by default. A remote, unauthenticated attacker in possession of a validly signed but expired bearer token can successfully authenticate to any endpoint using 'jwt.verify()'. This bypasses session management controls such as timeouts and manual revocations. The issue is resolved in version 0.5.1166.

Affected products

  • PerryTS Perry < 0.5.1166

Timeline

  • 2026-06-14: patched: Version 0.5.1166 released
  • 2026-06-16: advisory: GHSA-5324-c68v-8w62 published
  • 2026-06-16: disclosed: CVE-2026-53776 published

References

Related threats