CWE-1275
AllowedSensitive Cookie with Improper SameSite Attribute
Abstraction: Variant · Status: Incomplete
The SameSite attribute for sensitive cookies is not set, or an insecure value is used.
49 vulnerabilities reference this CWE, most recent first.
CVE-2022-38386 (GCVE-0-2022-38386)
Vulnerability from cvelistv5 – Published: 2024-05-01 12:48 – Updated: 2024-08-03 10:54- CWE-1275 - Sensitive Cookie with Improper SameSite Attribute
| URL | Tags |
|---|---|
| https://www.ibm.com/support/pages/node/7149811 | vendor-advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilit… | vdb-entry |
| Vendor | Product | Version | |
|---|---|---|---|
| IBM | Cloud Pak for Security |
Affected:
1.10.0.0 , ≤ 1.10.11.0
(semver)
|
|
| IBM | QRadar Suite for Software |
Affected:
1.10.12.0 , ≤ 1.10.19.0
(semver)
|
|
| ibm | cloud_pak_for_security |
Affected:
1.10.0.0 , ≤ 1.10.11.0
(semver)
cpe:2.3:a:ibm:cloud_pak_for_security:1.10.0.0:*:*:*:*:*:*:* |
|
| ibm | qradar_suite |
Affected:
1.10.12.0 , ≤ 1.10.19.0
(semver)
cpe:2.3:a:ibm:qradar_suite:1.10.12.0:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:ibm:cloud_pak_for_security:1.10.0.0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "cloud_pak_for_security",
"vendor": "ibm",
"versions": [
{
"lessThanOrEqual": "1.10.11.0",
"status": "affected",
"version": "1.10.0.0",
"versionType": "semver"
}
]
},
{
"cpes": [
"cpe:2.3:a:ibm:qradar_suite:1.10.12.0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "qradar_suite",
"vendor": "ibm",
"versions": [
{
"lessThanOrEqual": "1.10.19.0",
"status": "affected",
"version": "1.10.12.0",
"versionType": "semver"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2022-38386",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-05-01T15:13:52.205598Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-06-04T17:16:50.033Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-03T10:54:03.704Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://www.ibm.com/support/pages/node/7149811"
},
{
"tags": [
"vdb-entry",
"x_transferred"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/233778"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Cloud Pak for Security",
"vendor": "IBM",
"versions": [
{
"lessThanOrEqual": "1.10.11.0",
"status": "affected",
"version": "1.10.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "QRadar Suite for Software",
"vendor": "IBM",
"versions": [
{
"lessThanOrEqual": "1.10.19.0",
"status": "affected",
"version": "1.10.12.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778."
}
],
"value": "IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1275",
"description": "CWE-1275 Sensitive Cookie with Improper SameSite Attribute",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-05-01T12:48:12.167Z",
"orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"shortName": "ibm"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.ibm.com/support/pages/node/7149811"
},
{
"tags": [
"vdb-entry"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/233778"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "IBM Cloud Pak for Security information disclosure",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"assignerShortName": "ibm",
"cveId": "CVE-2022-38386",
"datePublished": "2024-05-01T12:48:12.167Z",
"dateReserved": "2022-08-16T18:42:49.432Z",
"dateUpdated": "2024-08-03T10:54:03.704Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
GHSA-26M8-335M-QJ22
Vulnerability from github – Published: 2025-03-26 09:31 – Updated: 2025-03-26 09:31HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).
{
"affected": [],
"aliases": [
"CVE-2024-30155"
],
"database_specific": {
"cwe_ids": [
"CWE-1275"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-26T08:15:12Z",
"severity": "MODERATE"
},
"details": "HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).",
"id": "GHSA-26m8-335m-qj22",
"modified": "2025-03-26T09:31:50Z",
"published": "2025-03-26T09:31:50Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30155"
},
{
"type": "WEB",
"url": "https://support.hcl-software.com/csm?id=kb_article\u0026sysparm_article=KB0120110"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-3FP6-H65V-MPRR
Vulnerability from github – Published: 2024-05-01 15:30 – Updated: 2024-05-01 15:30IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778.
{
"affected": [],
"aliases": [
"CVE-2022-38386"
],
"database_specific": {
"cwe_ids": [
"CWE-1275"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-01T13:15:47Z",
"severity": "MODERATE"
},
"details": "IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778.",
"id": "GHSA-3fp6-h65v-mprr",
"modified": "2024-05-01T15:30:34Z",
"published": "2024-05-01T15:30:34Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38386"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/233778"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7149811"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-53CV-4FRM-9P27
Vulnerability from github – Published: 2026-08-27 06:31 – Updated: 2026-08-27 18:32A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
{
"affected": [],
"aliases": [
"CVE-2026-47889"
],
"database_specific": {
"cwe_ids": [
"CWE-1275"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-08-27T06:17:19Z",
"severity": "HIGH"
},
"details": "A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19",
"id": "GHSA-53cv-4frm-9p27",
"modified": "2026-08-27T18:32:10Z",
"published": "2026-08-27T06:31:34Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47889"
},
{
"type": "WEB",
"url": "https://spring.io/security/cve-2026-47889"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-5R8W-HMFJ-P69P
Vulnerability from github – Published: 2024-10-22 18:32 – Updated: 2024-10-22 18:32IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
{
"affected": [],
"aliases": [
"CVE-2024-43173"
],
"database_specific": {
"cwe_ids": [
"CWE-1275"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-22T15:15:06Z",
"severity": "LOW"
},
"details": "IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.",
"id": "GHSA-5r8w-hmfj-p69p",
"modified": "2024-10-22T18:32:11Z",
"published": "2024-10-22T18:32:11Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43173"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7173596"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-9F25-WFQC-782V
Vulnerability from github – Published: 2025-03-10 12:30 – Updated: 2025-03-24 15:30A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation.
This issue affects:
- OTRS 7.0.X
- OTRS 8.0.X
- OTRS 2023.X
- OTRS 2024.X
- OTRS 2025.x
{
"affected": [],
"aliases": [
"CVE-2025-24387"
],
"database_specific": {
"cwe_ids": [
"CWE-1275",
"CWE-352"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-10T10:15:14Z",
"severity": "MODERATE"
},
"details": "A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive \ncookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation.\n\u00a0\n\nThis issue affects:\n\n * OTRS 7.0.X\n * OTRS 8.0.X\n * OTRS 2023.X\n * OTRS 2024.X\n * OTRS 2025.x",
"id": "GHSA-9f25-wfqc-782v",
"modified": "2025-03-24T15:30:38Z",
"published": "2025-03-10T12:30:55Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24387"
},
{
"type": "WEB",
"url": "https://otrs.com/release-notes/otrs-security-advisory-2025-05"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-C6MV-WGP4-CGJ2
Vulnerability from github – Published: 2025-05-05 21:31 – Updated: 2025-05-05 21:31HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user's browser into making unintended requests using authenticated sessions.
{
"affected": [],
"aliases": [
"CVE-2024-42212"
],
"database_specific": {
"cwe_ids": [
"CWE-1275"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-05T19:15:55Z",
"severity": "MODERATE"
},
"details": "HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site could trick a user\u0027s browser into making unintended requests using authenticated sessions.",
"id": "GHSA-c6mv-wgp4-cgj2",
"modified": "2025-05-05T21:31:28Z",
"published": "2025-05-05T21:31:28Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42212"
},
{
"type": "WEB",
"url": "https://support.hcl-software.com/csm?id=kb_article\u0026sysparm_article=KB0120961"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-CV8H-R7R5-VWJ9
Vulnerability from github – Published: 2025-12-19 21:30 – Updated: 2026-02-20 18:25Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.
{
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "kimai/kimai"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.30.10"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2023-53957"
],
"database_specific": {
"cwe_ids": [
"CWE-1275"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-20T18:25:02Z",
"nvd_published_at": "2025-12-19T21:15:52Z",
"severity": "HIGH"
},
"details": "Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.",
"id": "GHSA-cv8h-r7r5-vwj9",
"modified": "2026-02-20T18:25:02Z",
"published": "2025-12-19T21:30:20Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53957"
},
{
"type": "PACKAGE",
"url": "https://github.com/kimai/kimai"
},
{
"type": "WEB",
"url": "https://www.exploit-db.com/exploits/51278"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/kimai-samesite-cookie-vulnerability-session-hijacking"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"type": "CVSS_V4"
}
],
"summary": "Kimai contains a SameSite cookie vulnerability"
}
GHSA-F9M8-CV68-674W
Vulnerability from github – Published: 2026-10-08 16:30 – Updated: 2026-10-08 16:30Impact
The cookie store decides whether a Domain attribute may be accepted using only the domain-matching rule of RFC 6265 Section 5.1.3, which asks whether the request host is the domain or ends with a dot followed by it. Section 5.3 step 5, which additionally requires rejecting a Domain that is a public suffix, is not implemented anywhere in the client.
So a host under a multi-label public suffix can set a cookie for the suffix itself, and the store then hands it to every other host under that suffix:
attacker.co.uk -> Set-Cookie: SID=attacker-value; Domain=co.uk; Path=/
bank.co.uk -> Cookie: SID=attacker-value
Domain=uk works the same way. The attacker needs only a site under the same suffix as the victim, which for suffixes such as co.uk, com.au, or github.io is trivially obtainable.
Depending on what the application does with the cookie, this is session fixation, or it overwrites a session the victim site set, or it lets the attacker plant a value the victim site trusts.
Affected versions
- 3.x: up to and including 3.0.12
- 2.x: up to and including 2.16.0
Relationship to CVE-2026-55688
CVE-2026-55688 (GHSA-m452-q8c9-rg2f) covered the direct form of this, where a host sets a Domain naming an unrelated host, and that form is genuinely fixed: attacker.co.uk can no longer set Domain=bank.co.uk, and this was verified as a control. What that fix did not add is the public suffix test, so setting Domain=co.uk still reaches bank.co.uk. This advisory covers only the residual.
Patches
Fixed in 3.0.13 on the 3.x line. The ICANN section of the Mozilla public suffix list is bundled with the client and a Domain matching it is rejected, honouring the list's wildcard and exception rules. The list is data and goes stale, so a suffix added upstream after a release is not recognised until the bundled copy is refreshed. The 2.x line is not yet fixed.
Workarounds
Do not share one CookieStore across origins that are not mutually trusted. Supplying a CookieStore implementation that rejects Domain values which are public suffixes also avoids it.
Details
ThreadSafeCookieStore.domainsMatch is requestDomain.equals(cookieDomain) || requestDomain.endsWith('.' + cookieDomain). It is used both to accept a Domain on storage and to select cookies for a request, and neither call site consults a public suffix list. A search of the client for any public suffix or effective TLD handling returns nothing.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 3.0.12"
},
"package": {
"ecosystem": "Maven",
"name": "org.asynchttpclient:async-http-client"
},
"ranges": [
{
"events": [
{
"introduced": "3.0.0"
},
{
"fixed": "3.0.13"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 2.16.0"
},
"package": {
"ecosystem": "Maven",
"name": "org.asynchttpclient:async-http-client"
},
"ranges": [
{
"events": [
{
"introduced": "2.0.0"
},
{
"fixed": "2.16.1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-107280"
],
"database_specific": {
"cwe_ids": [
"CWE-1275"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-08T16:30:53Z",
"nvd_published_at": "2026-10-07T22:17:03Z",
"severity": "MODERATE"
},
"details": "### Impact\nThe cookie store decides whether a `Domain` attribute may be accepted using only the domain-matching rule of RFC 6265 Section 5.1.3, which asks whether the request host is the domain or ends with a dot followed by it. Section 5.3 step 5, which additionally requires rejecting a `Domain` that is a public suffix, is not implemented anywhere in the client.\n\nSo a host under a multi-label public suffix can set a cookie for the suffix itself, and the store then hands it to every other host under that suffix:\n\n```\nattacker.co.uk -\u003e Set-Cookie: SID=attacker-value; Domain=co.uk; Path=/\nbank.co.uk -\u003e Cookie: SID=attacker-value\n```\n\n`Domain=uk` works the same way. The attacker needs only a site under the same suffix as the victim, which for suffixes such as `co.uk`, `com.au`, or `github.io` is trivially obtainable.\n\nDepending on what the application does with the cookie, this is session fixation, or it overwrites a session the victim site set, or it lets the attacker plant a value the victim site trusts.\n\n### Affected versions\n* 3.x: up to and including 3.0.12\n* 2.x: up to and including 2.16.0\n\n### Relationship to CVE-2026-55688\nCVE-2026-55688 (GHSA-m452-q8c9-rg2f) covered the direct form of this, where a host sets a `Domain` naming an unrelated host, and that form is genuinely fixed: `attacker.co.uk` can no longer set `Domain=bank.co.uk`, and this was verified as a control. What that fix did not add is the public suffix test, so setting `Domain=co.uk` still reaches `bank.co.uk`. This advisory covers only the residual.\n\n### Patches\nFixed in 3.0.13 on the 3.x line. The ICANN section of the Mozilla public suffix list is bundled with the client and a `Domain` matching it is rejected, honouring the list\u0027s wildcard and exception rules. The list is data and goes stale, so a suffix added upstream after a release is not recognised until the bundled copy is refreshed. The 2.x line is not yet fixed.\n\n### Workarounds\nDo not share one `CookieStore` across origins that are not mutually trusted. Supplying a `CookieStore` implementation that rejects `Domain` values which are public suffixes also avoids it.\n\n### Details\n`ThreadSafeCookieStore.domainsMatch` is `requestDomain.equals(cookieDomain) || requestDomain.endsWith(\u0027.\u0027 + cookieDomain)`. It is used both to accept a `Domain` on storage and to select cookies for a request, and neither call site consults a public suffix list. A search of the client for any public suffix or effective TLD handling returns nothing.",
"id": "GHSA-f9m8-cv68-674w",
"modified": "2026-10-08T16:30:53Z",
"published": "2026-10-08T16:30:53Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-f9m8-cv68-674w"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107280"
},
{
"type": "WEB",
"url": "https://github.com/AsyncHttpClient/async-http-client/commit/330267895fe0bdb41bbd027ea6b151d38ee7c23d"
},
{
"type": "WEB",
"url": "https://github.com/AsyncHttpClient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f"
},
{
"type": "PACKAGE",
"url": "https://github.com/AsyncHttpClient/async-http-client"
},
{
"type": "WEB",
"url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"
},
{
"type": "WEB",
"url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N",
"type": "CVSS_V4"
}
],
"summary": "AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so a cookie can be set for co.uk"
}
GHSA-FM3F-CH8H-QW8Q
Vulnerability from github – Published: 2026-08-31 20:30 – Updated: 2026-08-31 20:30Summary
The built-in social login providers accept an OAuth callback even when the state value is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine login attempt. This defeats the state-based CSRF protection under default usage.
Details
The state check treated two absent values as a match, so a callback that omits state — and for which no state was ever stored — was allowed to redeem the authorization code. Hono's csrf() middleware does not help: it only inspects form-style requests, while the OAuth callback is a top-level GET navigation it treats as safe.
This affects the google, github, facebook, discord, twitch, linkedin, and msentra providers. The x (Twitter) provider is not exploitable due to its PKCE binding.
Impact
An attacker can make a victim's browser complete an OAuth callback that binds the attacker's identity instead of the victim's, leading to login CSRF (the victim silently acts inside the attacker's account) or forced account linking (the attacker's identity is linked to the victim's account, enabling later sign-in as the victim). Affects applications using an affected provider on @hono/oauth-providers 0.8.5 or earlier.
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "@hono/oauth-providers"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.8.6"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-81888"
],
"database_specific": {
"cwe_ids": [
"CWE-1275",
"CWE-352"
],
"github_reviewed": true,
"github_reviewed_at": "2026-08-31T20:30:50Z",
"nvd_published_at": null,
"severity": "MODERATE"
},
"details": "### Summary\n\nThe built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine login attempt. This defeats the `state`-based CSRF protection under default usage.\n\n### Details\n\nThe `state` check treated two absent values as a match, so a callback that omits `state` \u2014 and for which no `state` was ever stored \u2014 was allowed to redeem the authorization code. Hono\u0027s `csrf()` middleware does not help: it only inspects form-style requests, while the OAuth callback is a top-level `GET` navigation it treats as safe.\n\nThis affects the `google`, `github`, `facebook`, `discord`, `twitch`, `linkedin`, and `msentra` providers. The `x` (Twitter) provider is not exploitable due to its PKCE binding.\n\n### Impact\n\nAn attacker can make a victim\u0027s browser complete an OAuth callback that binds the attacker\u0027s identity instead of the victim\u0027s, leading to login CSRF (the victim silently acts inside the attacker\u0027s account) or forced account linking (the attacker\u0027s identity is linked to the victim\u0027s account, enabling later sign-in as the victim). Affects applications using an affected provider on `@hono/oauth-providers` `0.8.5` or earlier.",
"id": "GHSA-fm3f-ch8h-qw8q",
"modified": "2026-08-31T20:30:50Z",
"published": "2026-08-31T20:30:50Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/honojs/middleware/security/advisories/GHSA-fm3f-ch8h-qw8q"
},
{
"type": "WEB",
"url": "https://github.com/honojs/middleware/pull/2040"
},
{
"type": "WEB",
"url": "https://github.com/honojs/middleware/commit/b37765f40b7bddb1d8fce39573b085222dea58c1"
},
{
"type": "PACKAGE",
"url": "https://github.com/honojs/middleware"
},
{
"type": "WEB",
"url": "https://github.com/honojs/middleware/releases/tag/%40hono%2Foauth-providers%400.8.6"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
"type": "CVSS_V3"
}
],
"summary": "@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking"
}
Mitigation
Set the SameSite attribute of a sensitive cookie to 'Lax' or 'Strict'. This instructs the browser to apply this cookie only to same-domain requests, which provides a good Defense in Depth against CSRF attacks. When the 'Lax' value is in use, cookies are also sent for top-level cross-domain navigation via HTTP GET, HEAD, OPTIONS, and TRACE methods, but not for other HTTP methods that are more like to cause side-effects of state mutation.
CAPEC-62: Cross Site Request Forgery
An attacker crafts malicious web links and distributes them (via web pages, email, etc.), typically in a targeted manner, hoping to induce users to click on the link and execute the malicious action against some third-party application. If successful, the action embedded in the malicious link will be processed and accepted by the targeted application with the users' privilege level. This type of attack leverages the persistence and implicit trust placed in user session cookies by many web applications today. In such an architecture, once the user authenticates to an application and a session cookie is created on the user's system, all following transactions for that session are authenticated using that cookie including potential actions initiated by an attacker and simply "riding" the existing session cookie.