Common Weakness Enumeration

CWE-1275

Allowed

Sensitive Cookie with Improper SameSite Attribute

Abstraction: Variant · Status: Incomplete

The SameSite attribute for sensitive cookies is not set, or an insecure value is used.

49 vulnerabilities reference this CWE, most recent first.

CVE-2022-38386 (GCVE-0-2022-38386)

Vulnerability from cvelistv5 – Published: 2024-05-01 12:48 – Updated: 2024-08-03 10:54
VLAI
Title
IBM Cloud Pak for Security information disclosure
Summary
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778.
SSVC
Exploitation: none Automatable: no Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-05-01 15:13 UTC
CWE
  • CWE-1275 - Sensitive Cookie with Improper SameSite Attribute
Impacted products
Vendor Product Version
IBM Cloud Pak for Security Affected: 1.10.0.0 , ≤ 1.10.11.0 (semver)
Create a notification for this product.
IBM QRadar Suite for Software Affected: 1.10.12.0 , ≤ 1.10.19.0 (semver)
Create a notification for this product.
ibm cloud_pak_for_security Affected: 1.10.0.0 , ≤ 1.10.11.0 (semver)
    cpe:2.3:a:ibm:cloud_pak_for_security:1.10.0.0:*:*:*:*:*:*:*
Create a notification for this product.
ibm qradar_suite Affected: 1.10.12.0 , ≤ 1.10.19.0 (semver)
    cpe:2.3:a:ibm:qradar_suite:1.10.12.0:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "affected": [
          {
            "cpes": [
              "cpe:2.3:a:ibm:cloud_pak_for_security:1.10.0.0:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "product": "cloud_pak_for_security",
            "vendor": "ibm",
            "versions": [
              {
                "lessThanOrEqual": "1.10.11.0",
                "status": "affected",
                "version": "1.10.0.0",
                "versionType": "semver"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:ibm:qradar_suite:1.10.12.0:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "product": "qradar_suite",
            "vendor": "ibm",
            "versions": [
              {
                "lessThanOrEqual": "1.10.19.0",
                "status": "affected",
                "version": "1.10.12.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2022-38386",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-05-01T15:13:52.205598Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-06-04T17:16:50.033Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T10:54:03.704Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://www.ibm.com/support/pages/node/7149811"
          },
          {
            "tags": [
              "vdb-entry",
              "x_transferred"
            ],
            "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/233778"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Cloud Pak for Security",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "1.10.11.0",
              "status": "affected",
              "version": "1.10.0.0",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "QRadar Suite for Software",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "1.10.19.0",
              "status": "affected",
              "version": "1.10.12.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques.  IBM X-Force ID:  233778."
            }
          ],
          "value": "IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques.  IBM X-Force ID:  233778."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-1275",
              "description": "CWE-1275 Sensitive Cookie with Improper SameSite Attribute",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2024-05-01T12:48:12.167Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.ibm.com/support/pages/node/7149811"
        },
        {
          "tags": [
            "vdb-entry"
          ],
          "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/233778"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "IBM Cloud Pak for Security information disclosure",
      "x_generator": {
        "engine": "Vulnogram 0.1.0-dev"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2022-38386",
    "datePublished": "2024-05-01T12:48:12.167Z",
    "dateReserved": "2022-08-16T18:42:49.432Z",
    "dateUpdated": "2024-08-03T10:54:03.704Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

GHSA-26M8-335M-QJ22

Vulnerability from github – Published: 2025-03-26 09:31 – Updated: 2025-03-26 09:31
VLAI
Details

HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-30155"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1275"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-03-26T08:15:12Z",
    "severity": "MODERATE"
  },
  "details": "HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).",
  "id": "GHSA-26m8-335m-qj22",
  "modified": "2025-03-26T09:31:50Z",
  "published": "2025-03-26T09:31:50Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30155"
    },
    {
      "type": "WEB",
      "url": "https://support.hcl-software.com/csm?id=kb_article\u0026sysparm_article=KB0120110"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-3FP6-H65V-MPRR

Vulnerability from github – Published: 2024-05-01 15:30 – Updated: 2024-05-01 15:30
VLAI
Details

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2022-38386"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1275"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-05-01T13:15:47Z",
    "severity": "MODERATE"
  },
  "details": "IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques.  IBM X-Force ID:  233778.",
  "id": "GHSA-3fp6-h65v-mprr",
  "modified": "2024-05-01T15:30:34Z",
  "published": "2024-05-01T15:30:34Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38386"
    },
    {
      "type": "WEB",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/233778"
    },
    {
      "type": "WEB",
      "url": "https://www.ibm.com/support/pages/node/7149811"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-53CV-4FRM-9P27

Vulnerability from github – Published: 2026-08-27 06:31 – Updated: 2026-08-27 18:32
VLAI
Details

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-47889"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1275"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-08-27T06:17:19Z",
    "severity": "HIGH"
  },
  "details": "A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19",
  "id": "GHSA-53cv-4frm-9p27",
  "modified": "2026-08-27T18:32:10Z",
  "published": "2026-08-27T06:31:34Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47889"
    },
    {
      "type": "WEB",
      "url": "https://spring.io/security/cve-2026-47889"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-5R8W-HMFJ-P69P

Vulnerability from github – Published: 2024-10-22 18:32 – Updated: 2024-10-22 18:32
VLAI
Details

IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-43173"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1275"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-10-22T15:15:06Z",
    "severity": "LOW"
  },
  "details": "IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.",
  "id": "GHSA-5r8w-hmfj-p69p",
  "modified": "2024-10-22T18:32:11Z",
  "published": "2024-10-22T18:32:11Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43173"
    },
    {
      "type": "WEB",
      "url": "https://www.ibm.com/support/pages/node/7173596"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-9F25-WFQC-782V

Vulnerability from github – Published: 2025-03-10 12:30 – Updated: 2025-03-24 15:30
VLAI
Details

A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation.  

This issue affects:

  • OTRS 7.0.X
  • OTRS 8.0.X
  • OTRS 2023.X
  • OTRS 2024.X
  • OTRS 2025.x
Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-24387"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1275",
      "CWE-352"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-03-10T10:15:14Z",
    "severity": "MODERATE"
  },
  "details": "A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive \ncookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation.\n\u00a0\n\nThis issue affects:\n\n  *  OTRS 7.0.X\n  *  OTRS 8.0.X\n  *  OTRS 2023.X\n  *  OTRS 2024.X\n  *  OTRS 2025.x",
  "id": "GHSA-9f25-wfqc-782v",
  "modified": "2025-03-24T15:30:38Z",
  "published": "2025-03-10T12:30:55Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24387"
    },
    {
      "type": "WEB",
      "url": "https://otrs.com/release-notes/otrs-security-advisory-2025-05"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-C6MV-WGP4-CGJ2

Vulnerability from github – Published: 2025-05-05 21:31 – Updated: 2025-05-05 21:31
VLAI
Details

HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-42212"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1275"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-05-05T19:15:55Z",
    "severity": "MODERATE"
  },
  "details": "HCL BigFix Compliance is affected by an improper or missing SameSite attribute.  This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user\u0027s browser into making unintended requests using authenticated sessions.",
  "id": "GHSA-c6mv-wgp4-cgj2",
  "modified": "2025-05-05T21:31:28Z",
  "published": "2025-05-05T21:31:28Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42212"
    },
    {
      "type": "WEB",
      "url": "https://support.hcl-software.com/csm?id=kb_article\u0026sysparm_article=KB0120961"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-CV8H-R7R5-VWJ9

Vulnerability from github – Published: 2025-12-19 21:30 – Updated: 2026-02-20 18:25
VLAI
Summary
Kimai contains a SameSite cookie vulnerability
Details

Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Packagist",
        "name": "kimai/kimai"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "1.30.10"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2023-53957"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1275"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-02-20T18:25:02Z",
    "nvd_published_at": "2025-12-19T21:15:52Z",
    "severity": "HIGH"
  },
  "details": "Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.",
  "id": "GHSA-cv8h-r7r5-vwj9",
  "modified": "2026-02-20T18:25:02Z",
  "published": "2025-12-19T21:30:20Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53957"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/kimai/kimai"
    },
    {
      "type": "WEB",
      "url": "https://www.exploit-db.com/exploits/51278"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/kimai-samesite-cookie-vulnerability-session-hijacking"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Kimai contains a SameSite cookie vulnerability"
}

GHSA-F9M8-CV68-674W

Vulnerability from github – Published: 2026-10-08 16:30 – Updated: 2026-10-08 16:30
VLAI
Summary
AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so a cookie can be set for co.uk
Details

Impact

The cookie store decides whether a Domain attribute may be accepted using only the domain-matching rule of RFC 6265 Section 5.1.3, which asks whether the request host is the domain or ends with a dot followed by it. Section 5.3 step 5, which additionally requires rejecting a Domain that is a public suffix, is not implemented anywhere in the client.

So a host under a multi-label public suffix can set a cookie for the suffix itself, and the store then hands it to every other host under that suffix:

attacker.co.uk  ->  Set-Cookie: SID=attacker-value; Domain=co.uk; Path=/
bank.co.uk      ->  Cookie: SID=attacker-value

Domain=uk works the same way. The attacker needs only a site under the same suffix as the victim, which for suffixes such as co.uk, com.au, or github.io is trivially obtainable.

Depending on what the application does with the cookie, this is session fixation, or it overwrites a session the victim site set, or it lets the attacker plant a value the victim site trusts.

Affected versions

  • 3.x: up to and including 3.0.12
  • 2.x: up to and including 2.16.0

Relationship to CVE-2026-55688

CVE-2026-55688 (GHSA-m452-q8c9-rg2f) covered the direct form of this, where a host sets a Domain naming an unrelated host, and that form is genuinely fixed: attacker.co.uk can no longer set Domain=bank.co.uk, and this was verified as a control. What that fix did not add is the public suffix test, so setting Domain=co.uk still reaches bank.co.uk. This advisory covers only the residual.

Patches

Fixed in 3.0.13 on the 3.x line. The ICANN section of the Mozilla public suffix list is bundled with the client and a Domain matching it is rejected, honouring the list's wildcard and exception rules. The list is data and goes stale, so a suffix added upstream after a release is not recognised until the bundled copy is refreshed. The 2.x line is not yet fixed.

Workarounds

Do not share one CookieStore across origins that are not mutually trusted. Supplying a CookieStore implementation that rejects Domain values which are public suffixes also avoids it.

Details

ThreadSafeCookieStore.domainsMatch is requestDomain.equals(cookieDomain) || requestDomain.endsWith('.' + cookieDomain). It is used both to accept a Domain on storage and to select cookies for a request, and neither call site consults a public suffix list. A search of the client for any public suffix or effective TLD handling returns nothing.

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 3.0.12"
      },
      "package": {
        "ecosystem": "Maven",
        "name": "org.asynchttpclient:async-http-client"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.0.0"
            },
            {
              "fixed": "3.0.13"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 2.16.0"
      },
      "package": {
        "ecosystem": "Maven",
        "name": "org.asynchttpclient:async-http-client"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.0.0"
            },
            {
              "fixed": "2.16.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-107280"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1275"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-08T16:30:53Z",
    "nvd_published_at": "2026-10-07T22:17:03Z",
    "severity": "MODERATE"
  },
  "details": "### Impact\nThe cookie store decides whether a `Domain` attribute may be accepted using only the domain-matching rule of RFC 6265 Section 5.1.3, which asks whether the request host is the domain or ends with a dot followed by it. Section 5.3 step 5, which additionally requires rejecting a `Domain` that is a public suffix, is not implemented anywhere in the client.\n\nSo a host under a multi-label public suffix can set a cookie for the suffix itself, and the store then hands it to every other host under that suffix:\n\n```\nattacker.co.uk  -\u003e  Set-Cookie: SID=attacker-value; Domain=co.uk; Path=/\nbank.co.uk      -\u003e  Cookie: SID=attacker-value\n```\n\n`Domain=uk` works the same way. The attacker needs only a site under the same suffix as the victim, which for suffixes such as `co.uk`, `com.au`, or `github.io` is trivially obtainable.\n\nDepending on what the application does with the cookie, this is session fixation, or it overwrites a session the victim site set, or it lets the attacker plant a value the victim site trusts.\n\n### Affected versions\n* 3.x: up to and including 3.0.12\n* 2.x: up to and including 2.16.0\n\n### Relationship to CVE-2026-55688\nCVE-2026-55688 (GHSA-m452-q8c9-rg2f) covered the direct form of this, where a host sets a `Domain` naming an unrelated host, and that form is genuinely fixed: `attacker.co.uk` can no longer set `Domain=bank.co.uk`, and this was verified as a control. What that fix did not add is the public suffix test, so setting `Domain=co.uk` still reaches `bank.co.uk`. This advisory covers only the residual.\n\n### Patches\nFixed in 3.0.13 on the 3.x line. The ICANN section of the Mozilla public suffix list is bundled with the client and a `Domain` matching it is rejected, honouring the list\u0027s wildcard and exception rules. The list is data and goes stale, so a suffix added upstream after a release is not recognised until the bundled copy is refreshed. The 2.x line is not yet fixed.\n\n### Workarounds\nDo not share one `CookieStore` across origins that are not mutually trusted. Supplying a `CookieStore` implementation that rejects `Domain` values which are public suffixes also avoids it.\n\n### Details\n`ThreadSafeCookieStore.domainsMatch` is `requestDomain.equals(cookieDomain) || requestDomain.endsWith(\u0027.\u0027 + cookieDomain)`. It is used both to accept a `Domain` on storage and to select cookies for a request, and neither call site consults a public suffix list. A search of the client for any public suffix or effective TLD handling returns nothing.",
  "id": "GHSA-f9m8-cv68-674w",
  "modified": "2026-10-08T16:30:53Z",
  "published": "2026-10-08T16:30:53Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-f9m8-cv68-674w"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107280"
    },
    {
      "type": "WEB",
      "url": "https://github.com/AsyncHttpClient/async-http-client/commit/330267895fe0bdb41bbd027ea6b151d38ee7c23d"
    },
    {
      "type": "WEB",
      "url": "https://github.com/AsyncHttpClient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/AsyncHttpClient/async-http-client"
    },
    {
      "type": "WEB",
      "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
    },
    {
      "type": "WEB",
      "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so a cookie can be set for co.uk"
}

GHSA-FM3F-CH8H-QW8Q

Vulnerability from github – Published: 2026-08-31 20:30 – Updated: 2026-08-31 20:30
VLAI
Summary
@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking
Details

Summary

The built-in social login providers accept an OAuth callback even when the state value is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine login attempt. This defeats the state-based CSRF protection under default usage.

Details

The state check treated two absent values as a match, so a callback that omits state — and for which no state was ever stored — was allowed to redeem the authorization code. Hono's csrf() middleware does not help: it only inspects form-style requests, while the OAuth callback is a top-level GET navigation it treats as safe.

This affects the google, github, facebook, discord, twitch, linkedin, and msentra providers. The x (Twitter) provider is not exploitable due to its PKCE binding.

Impact

An attacker can make a victim's browser complete an OAuth callback that binds the attacker's identity instead of the victim's, leading to login CSRF (the victim silently acts inside the attacker's account) or forced account linking (the attacker's identity is linked to the victim's account, enabling later sign-in as the victim). Affects applications using an affected provider on @hono/oauth-providers 0.8.5 or earlier.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "@hono/oauth-providers"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.8.6"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-81888"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1275",
      "CWE-352"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-08-31T20:30:50Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
  },
  "details": "### Summary\n\nThe built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine login attempt. This defeats the `state`-based CSRF protection under default usage.\n\n### Details\n\nThe `state` check treated two absent values as a match, so a callback that omits `state` \u2014 and for which no `state` was ever stored \u2014 was allowed to redeem the authorization code. Hono\u0027s `csrf()` middleware does not help: it only inspects form-style requests, while the OAuth callback is a top-level `GET` navigation it treats as safe.\n\nThis affects the `google`, `github`, `facebook`, `discord`, `twitch`, `linkedin`, and `msentra` providers. The `x` (Twitter) provider is not exploitable due to its PKCE binding.\n\n### Impact\n\nAn attacker can make a victim\u0027s browser complete an OAuth callback that binds the attacker\u0027s identity instead of the victim\u0027s, leading to login CSRF (the victim silently acts inside the attacker\u0027s account) or forced account linking (the attacker\u0027s identity is linked to the victim\u0027s account, enabling later sign-in as the victim). Affects applications using an affected provider on `@hono/oauth-providers` `0.8.5` or earlier.",
  "id": "GHSA-fm3f-ch8h-qw8q",
  "modified": "2026-08-31T20:30:50Z",
  "published": "2026-08-31T20:30:50Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/honojs/middleware/security/advisories/GHSA-fm3f-ch8h-qw8q"
    },
    {
      "type": "WEB",
      "url": "https://github.com/honojs/middleware/pull/2040"
    },
    {
      "type": "WEB",
      "url": "https://github.com/honojs/middleware/commit/b37765f40b7bddb1d8fce39573b085222dea58c1"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/honojs/middleware"
    },
    {
      "type": "WEB",
      "url": "https://github.com/honojs/middleware/releases/tag/%40hono%2Foauth-providers%400.8.6"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking"
}

Mitigation
Implementation

Set the SameSite attribute of a sensitive cookie to 'Lax' or 'Strict'. This instructs the browser to apply this cookie only to same-domain requests, which provides a good Defense in Depth against CSRF attacks. When the 'Lax' value is in use, cookies are also sent for top-level cross-domain navigation via HTTP GET, HEAD, OPTIONS, and TRACE methods, but not for other HTTP methods that are more like to cause side-effects of state mutation.

CAPEC-62: Cross Site Request Forgery

An attacker crafts malicious web links and distributes them (via web pages, email, etc.), typically in a targeted manner, hoping to induce users to click on the link and execute the malicious action against some third-party application. If successful, the action embedded in the malicious link will be processed and accepted by the targeted application with the users' privilege level. This type of attack leverages the persistence and implicit trust placed in user session cookies by many web applications today. In such an architecture, once the user authenticates to an application and a session cookie is created on the user's system, all following transactions for that session are authenticated using that cookie including potential actions initiated by an attacker and simply "riding" the existing session cookie.