216.73.216.6

CVE-2025-54592

· Published 29/09/2025 22:15 · Modified 30/09/2025 14:15

Labels: CVE-2025-54592 2025-09-29CVE-2025-54592CWE-613[email protected]

Essential information

Published
29/09/2025 22:15
Modified
30/09/2025 14:15
Author
Creator
CVSS
8.8 HIGH (v3) 8.8 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during logout. After a user logs out, the session cookie remains active and unchanged. The unchanged cookie could be reused by an attacker if a new session were to be started. This failure to invalidate the session can lead to session hijacking and fixation vulnerabilities. This issue is fixed in version 1.27.0

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
freshrss / freshrss cpe:2.3:a:freshrss:freshrss:1.26.*:*:*:*:*:*:*:*
freshrss / freshrss cpe:2.3:a:freshrss:freshrss:<1.27.0:*:*:*:*:*:*:*

References