CVE-2025-4643
published 2025-08-29CVE-2025-4643: Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to…
PriorityP336medium6.3CVSS 4.0
AVNACHATNPRNUINVCLVILVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.40%
32.9th percentile
Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until expiration date (which is by default set to 2 hours, but can be changed).
This issue has been fixed in version 3.44.0 of Payload.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| payload_cms | payload | < 3.44.0 | 3.44.0 |
| payloadcms | graphql | >= 0 < 3.44.0 | 3.44.0 |
| payloadcms | next | >= 0 < 3.44.0 | 3.44.0 |
| payloadcms | payload | >= 0 < 3.44.0 | 3.44.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Payload does not invalidate JWTs after log out
osv·2025-08-29
CVE-2025-4643 [MEDIUM] Payload does not invalidate JWTs after log out
Payload does not invalidate JWTs after log out
Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until expiration date (which is by default set to 2 hours, but can be changed).
This issue has been fixed in version 3.44.0 of Payload.
GHSA
Payload does not invalidate JWTs after log out
ghsa·2025-08-29
CVE-2025-4643 [MEDIUM] CWE-613 Payload does not invalidate JWTs after log out
Payload does not invalidate JWTs after log out
Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until expiration date (which is by default set to 2 hours, but can be changed).
This issue has been fixed in version 3.44.0 of Payload.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-29
Published