Vulnerability Description
A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc.go of the component OIDC Session Cookie Handler. Executing a manipulation can lead to sensitive cookie without secure attribute. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult. The reported GitHub issue was closed with the label "not planned".
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/TwiN/gatus/
- https://github.com/TwiN/gatus/issues/1689
- https://vuldb.com/cve/CVE-2026-11956
- https://vuldb.com/submit/836328
- https://vuldb.com/vuln/370343
- https://vuldb.com/vuln/370343/cti
- https://github.com/TwiN/gatus/issues/1689
- https://vuldb.com/submit/836328
FAQ
What is CVE-2026-11956?
CVE-2026-11956 is a vulnerability with a CVSS score of 3.7 (LOW). A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc.go of the component OIDC Session Cookie Handler. Executing a manipulation can l...
How severe is CVE-2026-11956?
CVE-2026-11956 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-11956?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.