<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 06:12:51 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-194483</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-194483</link>
      <description>EUVD-2026-194483</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-194483</guid>
    </item>
    <item>
      <title>fkie_cve-2024-47833</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-47833</link>
      <description>&lt;p&gt;Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. This issue has been addressed in release version 4.0.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. This issue has been addressed in release version 4.0.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-47833</guid>
    </item>
    <item>
      <title>GHSA-r3jq-4r5c-j9hp — Taipy has a Session Cookie without Secure and HTTPOnly flags</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r3jq-4r5c-j9hp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: taipy&lt;/p&gt;
&lt;p&gt;### Summary
Session cookie is without Secure and HTTPOnly flags.&lt;/p&gt;
&lt;p&gt;### Details
Please take a look at this part of code (PoC screenshot) or check code directly (provided in Occurrences section below)&lt;/p&gt;
&lt;p&gt;**Occurrences**:
https://github.com/Avaiga/taipy/blob/develop/frontend/taipy-gui/src/components/Taipy/Navigate.tsx#L67&lt;/p&gt;
&lt;p&gt;**Proposed remediation:** add Secure and HTTPOnly flags for cookies.&lt;/p&gt;
&lt;p&gt;It could be like this:
document.cookie = `tprh=${tprh};path=/;Secure;HttpOnly;`;&lt;/p&gt;
&lt;p&gt;### PoC
**Screenshot**:
![image](https://github.com/Avaiga/taipy/assets/18367606/ea7d1bbd-ba27-447f-932b-3d33ffc1a2e7)&lt;/p&gt;
&lt;p&gt;### Impact
**Secure**: This flag indicates that the cookie should only be sent over secure HTTPS connections. Without this flag, the cookie will be sent over both HTTP and HTTPS connections, which could expose it to interception or tampering if the connection is not secure.
**HttpOnly:** This flag prevents the cookie from being accessed by client-side JavaScript. It helps mitigate certain types of attacks, such as cross-site scripting (XSS), by preventing malicious scripts from accessing the cookie&amp;#39;s value.&lt;/p&gt;
&lt;p&gt;**References**
    CWE-614: Sensitive Cookie in HTTPS Session Without &amp;#39;Secure&amp;#39; Attribute https://cwe.mitre.org/data/definitions/614.html
    CWE-1004: Sensitive Cookie Without &amp;#39;HttpOnly&amp;#39; Flag - https://cwe.mitre.org/data/definitions/1004.html
    OWASP - Secure Cookie Attribute - https://owasp.org/www-community/controls/SecureCookieAttribute
    Cookie security flags - https://www.invicti.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: taipy&lt;/p&gt;
&lt;p&gt;### Summary
Session cookie is without Secure and HTTPOnly flags.&lt;/p&gt;
&lt;p&gt;### Details
Please take a look at this part of code (PoC screenshot) or check code directly (provided in Occurrences section below)&lt;/p&gt;
&lt;p&gt;**Occurrences**:
https://github.com/Avaiga/taipy/blob/develop/frontend/taipy-gui/src/components/Taipy/Navigate.tsx#L67&lt;/p&gt;
&lt;p&gt;**Proposed remediation:** add Secure and HTTPOnly flags for cookies.&lt;/p&gt;
&lt;p&gt;It could be like this:
document.cookie = `tprh=${tprh};path=/;Secure;HttpOnly;`;&lt;/p&gt;
&lt;p&gt;### PoC
**Screenshot**:
![image](https://github.com/Avaiga/taipy/assets/18367606/ea7d1bbd-ba27-447f-932b-3d33ffc1a2e7)&lt;/p&gt;
&lt;p&gt;### Impact
**Secure**: This flag indicates that the cookie should only be sent over secure HTTPS connections. Without this flag, the cookie will be sent over both HTTP and HTTPS connections, which could expose it to interception or tampering if the connection is not secure.
**HttpOnly:** This flag prevents the cookie from being accessed by client-side JavaScript. It helps mitigate certain types of attacks, such as cross-site scripting (XSS), by preventing malicious scripts from accessing the cookie&amp;#39;s value.&lt;/p&gt;
&lt;p&gt;**References**
    CWE-614: Sensitive Cookie in HTTPS Session Without &amp;#39;Secure&amp;#39; Attribute https://cwe.mitre.org/data/definitions/614.html
    CWE-1004: Sensitive Cookie Without &amp;#39;HttpOnly&amp;#39; Flag - https://cwe.mitre.org/data/definitions/1004.html
    OWASP - Secure Cookie Attribute - https://owasp.org/www-community/controls/SecureCookieAttribute
    Cookie security flags - https://www.invicti.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r3jq-4r5c-j9hp</guid>
    </item>
    <item>
      <title>PYSEC-2024-168</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2024-168</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: taipy&lt;/p&gt;
&lt;p&gt;Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. This issue has been addressed in release version 4.0.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: taipy&lt;/p&gt;
&lt;p&gt;Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. This issue has been addressed in release version 4.0.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2024-168</guid>
    </item>
  </channel>
</rss>
