UNKNOWN NVD
CVE-2026-79313
webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead o
webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result, an expired session whose record has not yet been cleaned up can still be replayed and used, allowing an attacker holding a previously valid session cookie to continue accessing protected resources after the configured idle timeout.
References
- https://github.com/lichoin/TraceLoom/blob/main/CVEs/CVE-2026-79313.md
- https://github.com/webpy/webpy
This unknown severity vulnerability was published on 2026-09-22 via NVD.
vulnfeed aggregates 14151 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.