Impact
A structural mismatch between stateless JWT validation engines and a high‑performance tagged cache causes the blacklist entries for revoked tokens to be prematurely evicted after two hours, or when a cache tag flush occurs. Because the cryptographic signatures of JWTs remain valid for fourteen days, an attacker who obtains a token can simply replay it after the blacklist has been cleared, enabling unauthorized access to protected API endpoints. The weakness originates from an improper handling of token expiry in the framework’s cache layer and is classified as a trust boundary violation.
Affected Systems
The issue affects macropay‑solutions maravel‑framework versions earlier than 10.74.0, the 20.x series that uses the same O(1) lazy eviction model, and any application that integrates tymon/jwt‑auth or a similar package for API token authentication and blacklist management. Native Laravel applications that employ cache tags under memory‑constrained or eviction‑capable environments may also be impacted.
Risk and Exploitability
With a CVSS score of 8.7, this vulnerability is considered high severity. The EPSS score is not available at this time and the vulnerability has not been listed in CISA’s KEV catalog. The likely attack vector is remote, via standard API traffic: an attacker uses a token that has been evicted from the blacklist after the two‑hour TTL or after a manual tag flush. No special privileges or code execution are required; the reuse of an existing token is sufficient to gain continued access to the system.
OpenCVE Enrichment