<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 21:24:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-186561</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-186561</link>
      <description>EUVD-2026-186561</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-186561</guid>
    </item>
    <item>
      <title>fkie_cve-2023-44400</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-44400</link>
      <description>&lt;p&gt;Uptime Kuma is a self-hosted monitoring tool. Prior to version 1.23.3, attackers with access to a user&amp;#39;s device can gain persistent account access. This is caused by missing verification of Session Tokens after password changes and/or elapsed inactivity periods. Version 1.23.3 has a patch for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Uptime Kuma is a self-hosted monitoring tool. Prior to version 1.23.3, attackers with access to a user&amp;#39;s device can gain persistent account access. This is caused by missing verification of Session Tokens after password changes and/or elapsed inactivity periods. Version 1.23.3 has a patch for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-44400</guid>
    </item>
    <item>
      <title>GHSA-g9v2-wqcj-j99g — Uptime Kuma has Persistentent User Sessions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g9v2-wqcj-j99g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: uptime-kuma&lt;/p&gt;
&lt;p&gt;# Summary&lt;/p&gt;
&lt;p&gt;Attackers with access to a users&amp;#39; device can gain persistent account access.
This is caused by missing verification of Session Tokens after password changes and/or elapsed inactivity-periods.&lt;/p&gt;
&lt;p&gt;# Details&lt;/p&gt;
&lt;p&gt;`uptime-kuma` sets JWT tokens for users after successful authentication.&lt;/p&gt;
&lt;p&gt;These tokens have the following design flaws:
- After successful login, a JWT token and it is stored in `sessionStorage` or `localStorage`. 
  Which of the two is decided based on the `Remember Me` button. 
  The users&amp;#39; token is valid without any time limitation, even after long periods of inactivity. 
  This increases the risk of session hijacking if, for example, a user forgets to log off and leaves the PC.
- sessions are only deleted on the client side after a user loggs out, meaning a local attacker could reuse said token with deep system access over the browser
- If a user changes a password
  - any previously logged in clients are not logged out
  - previously issued tokens remained valid forever&lt;/p&gt;
&lt;p&gt;These flaws allow user cookies to remain valid even after changing passwords or being inactive, posing a high security risk.&lt;/p&gt;
&lt;p&gt;# POC
### Password resets not deactivating cookies
- Log in.
- Note the user cookie.
- Change your password.
- Attempt to log in again with the same cookie.
- The cookie remains valid despite the password change.&lt;/p&gt;
&lt;p&gt;### Inactivity not deactivating sessions
 In testing, even after a period of over a day of inactivity, the session was still valid&lt;/p&gt;
&lt;p&gt;# Impact&lt;/p&gt;
&lt;p&gt;Another person…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: uptime-kuma&lt;/p&gt;
&lt;p&gt;# Summary&lt;/p&gt;
&lt;p&gt;Attackers with access to a users&amp;#39; device can gain persistent account access.
This is caused by missing verification of Session Tokens after password changes and/or elapsed inactivity-periods.&lt;/p&gt;
&lt;p&gt;# Details&lt;/p&gt;
&lt;p&gt;`uptime-kuma` sets JWT tokens for users after successful authentication.&lt;/p&gt;
&lt;p&gt;These tokens have the following design flaws:
- After successful login, a JWT token and it is stored in `sessionStorage` or `localStorage`. 
  Which of the two is decided based on the `Remember Me` button. 
  The users&amp;#39; token is valid without any time limitation, even after long periods of inactivity. 
  This increases the risk of session hijacking if, for example, a user forgets to log off and leaves the PC.
- sessions are only deleted on the client side after a user loggs out, meaning a local attacker could reuse said token with deep system access over the browser
- If a user changes a password
  - any previously logged in clients are not logged out
  - previously issued tokens remained valid forever&lt;/p&gt;
&lt;p&gt;These flaws allow user cookies to remain valid even after changing passwords or being inactive, posing a high security risk.&lt;/p&gt;
&lt;p&gt;# POC
### Password resets not deactivating cookies
- Log in.
- Note the user cookie.
- Change your password.
- Attempt to log in again with the same cookie.
- The cookie remains valid despite the password change.&lt;/p&gt;
&lt;p&gt;### Inactivity not deactivating sessions
 In testing, even after a period of over a day of inactivity, the session was still valid&lt;/p&gt;
&lt;p&gt;# Impact&lt;/p&gt;
&lt;p&gt;Another person…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g9v2-wqcj-j99g</guid>
    </item>
    <item>
      <title>gsd-2023-44400</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-44400</link>
      <description>gsd-2023-44400</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-44400</guid>
    </item>
  </channel>
</rss>
