CVE-2026-19896

A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the file dtale/app.py of the component Flask Session Cookie. This manipulation causes insufficiently random values. Remote exploitation of the attack is possible. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-15 15:16

Updated : 2026-08-20 12:48


NVD link : CVE-2026-19896

Mitre link : CVE-2026-19896

CVE.ORG link : CVE-2026-19896


JSON object : View

Products Affected

No product.

CWE
CWE-310

Cryptographic Issues

CWE-330

Use of Insufficiently Random Values