Vulnerability Description
The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity timeout. Sessions persisted indefinitely after login, even after the OIDC access token expired. This vulnerability is fixed in 2.1.0.
Related Weaknesses (CWE)
References
- https://dsf.dev/operations/v2.1.0/bpe/oidc.html
- https://dsf.dev/operations/v2.1.0/fhir/oidc.html
- https://github.com/datasharingframework/dsf/commit/f4ecb002f7d12642f92da6b79371e
- https://github.com/datasharingframework/dsf/security/advisories/GHSA-gj7p-595x-q
FAQ
What is CVE-2026-40939?
CVE-2026-40939 is a documented vulnerability. The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity t...
How severe is CVE-2026-40939?
CVSS scoring is not yet available for CVE-2026-40939. Check NVD for updates.
Is there a patch for CVE-2026-40939?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.