CWE-324: Use of a Key Past its Expiration Date
The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.
19 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-31123 — Zitadel Expired JWT Keys Usable for Authorization Grants
- CVE-2025-2291 — PgBouncer default auth_query does not take Postgres password expiry into account
- CVE-2026-39923 — Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset
- CVE-2025-33012 — IBM Db2 improper account lockout
- CVE-2026-52809 — Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
- CVE-2026-54787 — sigstore-go fails to check signature timestamps against a signing key's validity period
- CVE-2024-38277 — moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate keys
Recently published
- CVE-2026-39923 — Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset
- CVE-2026-54787 — sigstore-go fails to check signature timestamps against a signing key's validity period
- CVE-2026-52809 — Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
- CVE-2025-33012 — IBM Db2 improper account lockout
- CVE-2025-2291 — PgBouncer default auth_query does not take Postgres password expiry into account
- CVE-2025-31123 — Zitadel Expired JWT Keys Usable for Authorization Grants
- CVE-2024-38277 — moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate keys