CVE-2025-4643: Lack of JWT Expiration after Log Out in PayloadCMS
Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until expiration date (which is by default set to 2 hours, but can be changed).
This issue has been fixed in version 3.44.0 of Payload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4643?
CVE-2025-4643 has a Medium severity rating due to the potential for token reuse after logout.
How do I fix CVE-2025-4643?
To fix CVE-2025-4643, implement token invalidation upon user logout in your authentication workflow.
Which versions of Payload are affected by CVE-2025-4643?
CVE-2025-4643 affects Payload versions prior to 3.44.0.
What is the impact of CVE-2025-4643?
The impact of CVE-2025-4643 allows attackers to reuse JSON Web Tokens after logout until their expiration.
How can I mitigate the risks of CVE-2025-4643?
Mitigating the risks of CVE-2025-4643 involves ensuring that JWTs are invalidated immediately upon user logout.