Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55617— Hydro: Insufficient session expiration when recreating sessions

Quick assessment

Affected
hydro-dev Hydro
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Hydro 是一个下一代高性能在线评测平台(OJ)。在 4.10.4 至 5.0.2 版本中, 中的会话重建逻辑在创建新的替代会话令牌时,未从服务器端的会话令牌存储中删除旧的令牌。因此,在登出或经过另一次续期流程后,旧的 Cookie 可能仍然保持有效。 持有受害者先前有效但已过期的旧 Cookie 的攻击者,可以在不知晓受害者用户名或密码、且在利用该漏洞时不需要受害者交互的情况下,通过 HTTP 或 HTTPS 重新播放(replay)该 Cookie。成功重放后,攻击者可以接管受害者的账户、泄露私密数据,并允许

CVSS 6.9 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
hydro-dev Hydro >= 4.10.4, < 5.0.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55617

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Hydro: Insufficient session expiration when recreating sessions
Source: CVE Program / CVE List V5
Vulnerability Description
Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a replacement session token without deleting the previous token from the server-side session token store, so an old sid cookie can remain valid after logout or another renewal flow. An attacker who possesses a victim's previously valid stale cookie can replay it over HTTP or HTTPS without knowing the victim's username or password and without victim interaction at exploitation time. Successful replay can take over the victim's account, disclose private data, and permit unauthorized modification or deletion of data available to that account. This issue is fixed in version 5.0.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的会话过期机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
hydro-dev Hydro >= 4.10.4, < 5.0.2 -

II. Public POCs for CVE-2026-55617

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55617

登录查看更多情报信息。

Patches & Fixes for CVE-2026-55617 (3)

Vendor Advisories for CVE-2026-55617 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-55617

No comments yet


Leave a comment