CRITICAL
9.8 CVE-2026-79313 Published 22 Sept 2026
web.py Session Expiration Bypass Lets Stale Sessions Be Replayed
Worried this affects your website?
web.py 0.76 is vulnerable to insufficient session expiration.
The framework's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result, an expired session whose record has not yet been cleaned up can still be replayed and used.
- An attacker holding a previously valid session cookie can continue accessing protected resources after the configured idle timeout.
Reference: CVE-2026-79313 on NVD
← Back to Security News