PT-2026-48659 · Unknown · Twin Gatus

·

CVE-2026-11956

·

Published

2026-06-11

·

Updated

2026-06-11

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions TwiN gatus version 5.36.0
Description A flaw exists in the OIDC Session Cookie Handler component within the setSessionCookie() function of the security/oidc.go file. A remote attacker can perform a high-complexity manipulation to cause sensitive cookies to be issued without the secure attribute, which ensures cookies are only transmitted over encrypted connections.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11956

Affected Products

Twin Gatus