CVE-2026-11956

Source
https://cve.org/CVERecord?id=CVE-2026-11956
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-11956.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-11956
Published
2026-06-11T11:30:12.019Z
Modified
2026-07-15T01:48:58.229151649Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
TwiN gatus OIDC Session Cookie oidc.go setSessionCookie missing secure attribute
Details

A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc.go of the component OIDC Session Cookie Handler. Executing a manipulation can lead to sensitive cookie without secure attribute. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult. The reported GitHub issue was closed with the label "not planned".

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/11xxx/CVE-2026-11956.json",
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-1004",
        "CWE-614"
    ]
}
References

Affected packages

Git / github.com/twin/gatus

Affected ranges

Type
GIT
Repo
https://github.com/twin/gatus
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "5.36.0"
        },
        {
            "last_affected": "5.36.0"
        }
    ]
}

Affected versions

5.*
5.36.0
v5.*
v5.36.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-11956.json"