Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-40171

23
FAUCET Score

CVE-2023-40171 is a high-severity vulnerability affecting Netflix Dispatch, an open-source security incident management tool. It allows for the disclosure of the JWT Secret Key in error messages when the Basic Authentication Provider plugin fails to decode a JWT token. This enables an attacker to craft valid JWTs, potentially leading to full account takeover within an affected Dispatch instance. The vulnerability has a CVSS score of 7.5, indicating a network-based attack with low complexity and high confidentiality impact. While a fix is available in the 20230817 release, there are no known workarounds, and there is currently no evidence of active exploitation, public exploit code, or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
< 20230817CPE matchmatch criteria
cpe:2.3:a:netflix:dispatch:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.76%
Probability of exploitation in next 30 days
EPSS Percentile
51.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0076 is in the 27th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / Netflix/dispatch/commit/b1942a4319f0de820d86b84a58ebc85398b97c70
Patch
github.com / Netflix/dispatch/pull/3695
Patch
github.com / Netflix/dispatch/releases/tag/latest
Release Notes
github.com / Netflix/dispatch/security/advisories/GHSA-fv3x-67q3-6pg7
ExploitThird Party Advisory