CVE-2026-55250
Deferred Deferred - Pending Action

Token Replay Vulnerability in Maravel Framework

Vulnerability report for CVE-2026-55250, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: GitHub, Inc.

Description

Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless token validation engines and high-performance relational caching layers. Any application with low cache memory that causes premature eviction to free up memory and applications running macropay-solutions/maravel-framework that utilize tymon/jwt-auth for API token authentication and blacklist management or any other package that does the same may be affected. This architectural risk might also impact native Laravel applications utilizing cache tags under specific volatile or eviction-capped environments. tymon/jwt-auth automatically probes for cache tag support. If found, it forcefully wraps 14-day token blacklist entries (jti) inside a relational tymon.jwt tag. In environments where the O(1) Atomic Lazy Eviction model is active β€” either natively inside Maravel-Framework v20.x or manually backported into v10.x via the explicit DI container singletons provided in PR #104 (App\Cache\TaggedCache and App\Cache\TagSet) β€” a strict global tracking ceiling (Container::TAGGED_CACHE_TTL_CAP_SECONDS) of 7,200 seconds (2 hours) is enforced to secure the system against memory index bloat. This ceiling forcefully truncates the 14-day blacklist lifespan down to a maximum of 2 hours, after which individual tracking keys naturally expire and disappear from the active cache window. Furthermore, because the optimized engine implements a generational version matrix to achieve O(1) flush speeds, any programmatic or manual invocation of a tag flush or reset (e.g., Cache::tags([...])->flush()) instantly bumps the internal atomic master version pointer. This shifts the computed cryptographic composite hash (sha1($this->tags->getNamespace())) for all overlapping components, rendering the entire existing index immediately unreachable. Consequently, through either natural 2-hour expiration or an intervening tag flush execution (like the cache naturally cleaning old values to free up memory), the invalidation state records are entirely wiped out. Because the tokens' physical cryptographic signatures remain structurally valid for up to 14 days, stolen, hijacked, or legitimately logged-out tokens are instantly and silently resurrected across the entire API gateway, leaving the application critically vulnerable to widespread Token Replay Attacks. Because this issue is caused by an upstream architectural assumption within the tymon/jwt-auth package rather than a core defect inside the framework, there is no direct framework version upgrade that can safely bypass this lifecycle collision without breaking business cache recycling bounds. Maravel version 10.74.0 introduced a way to backport the new fixed tagged cache from 20.x into 10.x by resolving TagSet and TaggedCache from DI, which is how this latent architectural lifecycle vulnerability was discovered. Users must apply the decoupled configuration workaround outlined below. As a workaround, make sure that cache memory size does not generate early natural evictions from cache to free up space, deleting blacklisted jwt ids before they expire. Applications must decouple flat authentication vectors from the relational tagging subsystem. This forces token identifiers to write directly to the primary cache keyspace as flat, un-tagged key-value pairs where they securely retain their unclipped 14-day lifecycle.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
maravel maravel to 10.74.0 (exc)
tymon jwt_auth *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-672 The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
CWE-294 A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Token Replay Attack in Maravel framework versions prior to 10.74.0. It occurs due to a mismatch between token validation systems and caching layers. When cache memory is low, tokens are prematurely evicted, but their cryptographic signatures remain valid for up to 14 days. This allows revoked or stolen tokens to be reused, bypassing authentication and exposing the system to replay attacks.

Detection Guidance

Detecting this vulnerability requires checking if your system uses Maravel framework versions prior to 10.74.0 with tymon/jwt-auth for JWT token authentication and blacklist management. Inspect cache configurations for tagged cache usage and verify if cache memory settings cause premature evictions. Check for active cache tags and blacklist entries with lifespans shorter than expected (e.g., 2 hours instead of 14 days).

  • Review Maravel framework version: composer show macropay-solutions/maravel-framework
  • Check JWT blacklist cache entries: php artisan cache:show tymon.jwt
  • Inspect cache tags configuration: grep -r "Cache::tags" app/
Impact Analysis

Attackers could exploit this to gain unauthorized access to your application by replaying valid but revoked tokens. This could lead to data breaches, unauthorized transactions, or privilege escalation. Systems using tymon/jwt-auth for token management or Laravel applications with cache tags in volatile environments are particularly at risk.

Compliance Impact

This vulnerability could violate compliance requirements for data protection and access control. GDPR mandates secure authentication and token revocation mechanisms, while HIPAA requires strict access controls. Failure to prevent token replay attacks may result in non-compliance, potential fines, and legal liabilities due to unauthorized data access.

Mitigation Strategies

Upgrade to Maravel version 10.74.0 or later. If upgrading is not possible, apply the decoupled configuration workaround by disabling cache tags for JWT blacklist entries. Ensure cache memory is sufficient to prevent premature evictions. Configure the system to store blacklist entries as flat key-value pairs instead of using tagged cache.

  • Update Maravel framework: composer require macropay-solutions/maravel-framework:^10.74.0
  • Disable tagged cache for JWT: Set 'jwt.blacklist_cache_tags' to false in configuration
  • Increase cache memory allocation to prevent evictions
  • Monitor cache entries: php artisan cache:monitor --hours=24

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55250. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart