CVE-2026-55617
Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a replacement session token without deleting the previous token from the server-side session token store, so an old sid cookie can remain valid after logout or another renewal flow. An attacker who possesses a victim's previously valid stale cookie can replay it over HTTP or HTTPS without knowing the victim's username or password and without victim interaction at exploitation time. Successful replay can take over the victim's account, disclose private data, and permit unauthorized modification or deletion of data available to that account. This issue is fixed in version 5.0.2.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-613
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- hydro-dev Hydro
Weakness type
Related vulnerabilities
- CVE-2026-1435 — Incorrect management of session invalidation vulnerability in Graylog Web Interface
- CVE-2024-13996 — Nagios XI < 2024R1.1.3 Session Not Invalidated After Password Change
- CVE-2026-27575 — Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change
- CVE-2026-34572 — CI4MS: Account Deactivation Module Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
- CVE-2026-26342 — Tattile Smart+ / Vega / Basic <= 1.181.5 Insufficient Session Token Expiration
- CVE-2026-24894 — FrankenPHP leaks session data between requests in worker mode
- CVE-2025-66289 — OrangeHRM is Vulnerable to Persistent Session Access Due to Missing Invalidation After User Disable and Password Change
- CVE-2025-66223 — OpenObserve's Invite Token Lifecycle Misconfiguration