CVE-2026-19896
Received Received - Intake

Insufficiently Random Values in D-Tale Flask Session Cookie

Vulnerability report for CVE-2026-19896, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-15

Assigner: VulDB

Description

A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the file dtale/app.py of the component Flask Session Cookie. This manipulation causes insufficiently random values. Remote exploitation of the attack is possible. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-15
Generated
2026-08-16
AI Q&A
2026-08-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mangroup dtale to 3.22.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-330 The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
CWE-310 Cryptographic Issues

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in mangroup dtale up to version 3.22.0, specifically in the Flask Session Cookie generation function build_secret_key in dtale/app.py. It allows insufficiently random values to be used, making session cookies predictable. The attack complexity is high but exploitation is possible remotely. An exploit has been published and a fix is pending.

Impact Analysis

An attacker could potentially predict or manipulate session cookies, leading to unauthorized access to user sessions. This could allow them to impersonate users, access sensitive data, or perform actions on behalf of legitimate users within the application.

Compliance Impact

This vulnerability may violate compliance requirements for data protection and session security, such as GDPR's data integrity and confidentiality principles or HIPAA's safeguards for protected health information. Unauthorized session access could lead to data breaches, triggering regulatory penalties and legal consequences.

Mitigation Strategies

Update mangroup dtale to a version beyond 3.22.0 where the fix has been applied. If no patched version is available, consider disabling the Flask Session Cookie functionality or restricting access to the vulnerable component until a patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19896. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart