CVE-2026-19896: mangroup dtale Flask Session Cookie app.py build_secret_key random values
A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function buildsecretkey of the file dtale/app.py of the component Flask Session Cookie. This manipulation causes insufficiently random values. Remote exploitation of the attack is possible. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19896?
CVE-2026-19896 has a severity rating of low, scored at 3.7.
How does CVE-2026-19896 affect the Flask Session Cookie?
CVE-2026-19896 affects the build_secret_key function in the Flask Session Cookie, leading to insufficiently random values.
Can CVE-2026-19896 be exploited remotely?
Yes, CVE-2026-19896 is vulnerable to remote exploitation.
What versions of mangroup dtale are affected by CVE-2026-19896?
CVE-2026-19896 affects mangroup dtale versions up to 3.22.0.
How can I mitigate the risk from CVE-2026-19896?
To mitigate the risk from CVE-2026-19896, ensure you upgrade to a fixed version of mangroup dtale.