216.73.216.6

CVE-2026-11956

· Published 11/06/2026 15:16 · Modified 11/06/2026 14:42 · Author: The MITRE Corporation

Labels: CVE-2026-11956 2026-06-11CVE-2026-11956CWE-614[email protected]

Essential information

Published
11/06/2026 15:16
Modified
11/06/2026 14:42
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
2.6 (v2) 3.7 LOW (v3.1) 6.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CWE-614
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS metrics

Description

A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc.go of the component OIDC Session Cookie Handler. Executing a manipulation can lead to sensitive cookie without secure attribute. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult. The reported GitHub issue was closed with the label "not planned".

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
twin / gatus cpe:2.3:a:twin:gatus:5.36.0:*:*:*:*:*:*:*

References