CWE-613
CVEs classified under CWE-613, newest first.
90 CVEsRSS
CVE-2026-53517High· 8.1Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
GHSA-2vg6-77g8-24mpLow· 3.8Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
GHSA-f9ff-5x35-7gfwHighGrackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
GHSA-275c-xpvc-jgfwMediumOpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
GHSA-4m3v-q747-pc6hMediumOpenClaw: Mattermost slash token revocation could lag until monitor refresh
OpenClaw: Mattermost slash token revocation could lag until monitor refresh
GHSA-4m82-p8cx-f94jMedium· 4.3SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
CVE-2026-52809Medium· 6.8Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
CVE-2026-9162Medium· 4.3Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation
Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation
CVE-2026-49229High· 8.3@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens
@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens
CVE-2026-12796Medium· 6.3BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
CVE-2026-12772Medium· 6.3LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
CVE-2026-54779Medium· 5.9CoreWCF: SAML token replay protection is inoperative
CoreWCF: SAML token replay protection is inoperative
CVE-2026-55423Medium· 6.1Langflow: Logout button does not clear session
Langflow: Logout button does not clear session
GHSA-wxg7-w2v3-w38gMedium· 4.2ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
CVE-2026-53928MediumNocoDB: Refresh Tokens Persist Through Password Recovery
NocoDB: Refresh Tokens Persist Through Password Recovery
CVE-2026-54321High· 7.0Daytona: Public sandbox previews remain accessible for up to one hour after being made private
Daytona: Public sandbox previews remain accessible for up to one hour after being made private
GHSA-wrmq-9fc4-gwwjHigh· 8.8Duplicate Advisory: Pairing-scoped device session could restore revoked node token authority
Duplicate Advisory: Pairing-scoped device session could restore revoked node token authority
CVE-2026-44648High· 7.5PoCSillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern relies on cookie-session …
CVE-2026-5545Medium· 6.5libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that sub…
libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that sub…
CVE-2026-34503High· 8.1OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked
OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced recon…
CVE-2025-25252Medium· 4.3An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose a…
CVE-2025-10223Medium· 5.4Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an u…
Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an u…
CVE-2025-4754Low· 2.3Insufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign-out to remain usable afterwards. The default sign_out/2 that AshAuthentication.Phoenix.Controller injec…
Insufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign-out to remain usable afterwards. The default sign_out/2 that AshAuthentication.Phoenix.Controller injec…
CVE-2025-4528Medium· 4.3A weakness has been identified in Dígitro NGC Explorer up to 3.48.21
A weakness has been identified in Dígitro NGC Explorer up to 3.48.21. This affects an unknown function. Executing a manipulation can lead to session expiration. The attack can be launched remotely. Upgrading to version 3.48.22 mitigates …
CVE-2022-34624Medium· 5.9Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.
CVE-2022-25590Medium· 6.5SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.
SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.
CVE-2021-32923Medium· 6.5vault: Token leases incorrectly treated as non-expiring (CVE-2021-32923)
A flaw was found in the HashiCorp Vault and Vault Enterprise. The vault could allow a remote attacker to bypass security restrictions caused by a renewal logic flaw when a token lease or dynamic secret lease was renewed inside the last sec…
CVE-2020-23136Medium· 5.5Microweber v1.1.18 is affected by no session expiry after log-out.
Microweber v1.1.18 is affected by no session expiry after log-out.
CVE-2020-3188Medium· 5.3A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for management connections could allow an unauthenticated, remote attacker to cause a buildup of remote management connections to an affected d…
A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for management connections could allow an unauthenticated, remote attacker to cause a buildup of remote management connections to an affected d…
CVE-2013-0335High· 7.6OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.