Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-613 (不充分的会话过期机制) — Vulnerability Class 414

414 vulnerabilities classified as CWE-613 (不充分的会话过期机制). AI Chinese analysis included.

CWE-613 represents a critical authentication weakness where web applications fail to properly invalidate session identifiers after a user logs out or after a period of inactivity. This flaw allows attackers to exploit stale session tokens, often obtained through network sniffing, session fixation, or simply waiting for a user to abandon a shared device. By reusing these expired credentials, adversaries can bypass authentication mechanisms and gain unauthorized access to sensitive user accounts or administrative functions without needing to crack passwords. To mitigate this risk, developers must implement robust session management protocols that enforce strict expiration policies. This includes setting appropriate timeout durations for both active and idle sessions, ensuring that logout actions immediately invalidate server-side session data, and utilizing secure, HttpOnly cookies to prevent client-side script access to session identifiers.

MITRE CWE Description
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Common Consequences (1)
Access Control Bypass Protection Mechanism
Mitigations (1)
Implementation Set sessions/credentials expiration date.
Examples (1)
The following snippet was taken from a J2EE web.xml deployment descriptor in which the session-timeout parameter is explicitly defined (the default value depends on the container). In this case the value is set to -1, which means that a session will never expire.
<web-app> [...snipped...] <session-config> <session-timeout>-1</session-timeout> </session-config> </web-app>
Bad · Java
CVE ID Title CVSS Severity Published
CVE-2026-66400 Grav Login Plugin before 3.8.13 Insufficient Session Expiration — grav 4.8 Medium 2026-07-29
CVE-2026-14996 Multiple vulnerabilities in IBM Aspera Faspex — Aspera Faspex 5 8.2 High 2026-07-28
CVE-2026-15967 MOVEit Transfer refresh-token processing does not enforce updated account restrictions — MOVEit Transfer 7.5 High 2026-07-23
CVE-2026-64829 Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow — question2answer 7.4 High 2026-07-22
CVE-2026-56583 HCL MyCloud was affected with Concurrent Login Vulnerability. — MyCloud 3.1 Low 2026-07-21
CVE-2026-63753 SurrealDB before 3.1.0 Authentication Bypass via LIVE Query — surrealdb 4.3 Medium 2026-07-20
CVE-2026-16206 django-oauth django-oauth-toolkit oauth2_validators.py _load_id_token session expiration — django-oauth-toolkit 6.3 Medium 2026-07-19
CVE-2026-63175 Cross-Capture Session Data Leakage Due to Shared Mutable State in Looklyloo - PlaywrightCapture — PlaywrightCapture - - 2026-07-15
CVE-2026-61452 Grav before 2.0.4 Improper Session Invalidation JWT Access Tokens — grav 5.3 Medium 2026-07-15
CVE-2026-56400 open-webui - Remote Code Execution via CORS Misconfiguration and Session Validation — open-webui 8.3 High 2026-07-15
CVE-2026-48329 ColdFusion | Insufficient Session Expiration (CWE-613) — ColdFusion 2025 2.7 Low 2026-07-14
CVE-2026-44383 Hydro-Québec Le Circuit Electrique charging station backend Insufficient Session Expiration — Le Circuit Electrique charging station backend 7.5 High 2026-07-10
CVE-2026-56665 ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider — zitadel 4.2 Medium 2026-07-10
CVE-2026-56664 ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider — zitadel 4.2 Medium 2026-07-10
CVE-2026-28564 Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials — Apache IoTDB - - 2026-07-10
CVE-2026-59219 Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout — open-webui 7.1 High 2026-07-09
CVE-2026-49229 Actual: Disabled OpenID users keep access through existing session tokens — actual 8.3 High 2026-07-07
CVE-2026-42172 Coolify: Sanctum API Tokens Have No Expiration — Leaked Tokens Grant Permanent Access — coolify 3.1 Low 2026-07-07
CVE-2026-43918 Suspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and password reset flows — FOSSBilling - - 2026-07-06
CVE-2026-46455 Apache Camel: Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted — Apache Camel - - 2026-07-06
CVE-2026-14725 SourceCodester Online Boat Reservation System session expiration — Online Boat Reservation System 6.3 Medium 2026-07-05
CVE-2025-36359 IBM DevOps Loop is susceptible to an Insufficient Session Expiration vulnerability. — DevOps Automation 8.1 High 2026-06-30
CVE-2025-71335 Flowise - Session Invalidation Failure After Password Change — Flowise 8.1 High 2026-06-25
CVE-2026-54479 EVoke Systems EVoke CSMS Insufficient Session Expiration — EVoke CSMS 7.3 High 2026-06-25
CVE-2026-9705 Keycloak: keycloak: attacker can re-enable and take over disabled clients via registration access token — Red Hat build of Keycloak 26.4 6.5 Medium 2026-06-25
CVE-2026-49277 Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation — Rocket.Chat - - 2026-06-24
CVE-2026-45757 Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens — Rocket.Chat - - 2026-06-24
CVE-2026-46554 NocoDB: Stale Auth Cache After API Token Deletion — nocodb - - 2026-06-23
CVE-2026-53926 NocoDB: OAuth Tokens Persist Through Security Events — nocodb - - 2026-06-23
CVE-2026-53928 NocoDB: Refresh Tokens Persist Through Password Recovery — nocodb - - 2026-06-23

Vulnerabilities classified as CWE-613 (不充分的会话过期机制) represent 414 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.