Junglewise Threat Intelligence

CVE-2026-79313: web.py insufficient session expiration in session loading

CVE-2026-79313 · Severity: critical · CVSS 9.8 · Published 2026-09-22

Executive brief

web.py is a Python web framework used to build web services and APIs. The framework's session management fails to validate when a session has expired during a timing window between when a session exceeds its idle timeout and when background cleanup removes the expired record. An attacker holding a previously valid session cookie can replay it after the configured timeout expires, gaining unauthorized access to protected resources until the next cleanup runs.

Technical details

The vulnerability is insufficient session expiration (CWE-613) in the session loading logic. When a session is restored for a request, the framework checks only whether the session record exists in the store but does not compare the record's last-access time against the idle timeout. An attacker who holds a session cookie can replay it after the idle timeout has passed, provided the background cleanup has not yet deleted the record. This requires network access and a previously valid session cookie, but no authentication or user interaction.

Affected products

  • webpy web.py 0.76, development branch

Timeline

  • 2026-08-04: disclosed
  • 2026-09-22: advisory

References

Related threats