webpy web.py 0.76 is vulnerable to Session Fixation. The...
Moderate severity
Unreviewed
Published
Sep 22, 2026
to the GitHub Advisory Database
•
Updated Sep 22, 2026
Description
Published by the National Vulnerability Database
Sep 22, 2026
Published to the GitHub Advisory Database
Sep 22, 2026
Last updated
Sep 22, 2026
webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the request cookie and loads that session from the store, and _save() writes back under the same session_id; no rotation after authentication, so a fixed session_id keeps the authenticated state.
References