Executive brief
Maravel, a PHP framework for building applications with dependency injection, contains a vulnerability in how it manages authentication tokens. When token blacklists are cached to improve performance, the cache layer can prematurely expire tokens before their intended 14-day lifetime ends, allowing attackers to reuse stolen or revoked authentication tokens to access APIs and gain unauthorized access to protected resources.
Technical details
The vulnerability is a token replay attack arising from a lifecycle mismatch between JWT token blacklist validation and the caching system. When tymon/jwt-auth integrates with Maravel's tagged cache layer, the framework enforces a 2-hour TTL cap (Container::TAGGED_CACHE_TTL_CAP_SECONDS) on blacklist entries, truncating the intended 14-day token lifetime. Additionally, cache tag flushes trigger a generational version matrix bump that invalidates all tracked blacklist entries, causing revoked tokens to be instantly "forgotten" by the system. Affected applications are those running Maravel versions prior to 10.74.0 with tymon/jwt-auth or equivalent JWT packages relying on cache tags for token blacklist management. The attack requires no authentication or network positioning beyond the ability to craft API requests with previously leaked tokens. Maravel 10.74.0 introduces backported fixes from version 20.x; users must apply the configuration workaround to decouple authentication vectors from the relational tagging subsystem and store token identifiers as flat, untagged cache entries.
Affected products
- Maravel Maravel Framework prior to 10.74.0
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory: CVE-2026-55250 published