A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the file dtale/app.py of the component Flask Session Cookie. This manipulation causes insufficiently random values. Remote exploitation of the attack is possible. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.

Project Subscriptions

Vendors Products
Mangroup Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 15 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the file dtale/app.py of the component Flask Session Cookie. This manipulation causes insufficiently random values. Remote exploitation of the attack is possible. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
Title mangroup dtale Flask Session Cookie app.py build_secret_key random values
First Time appeared Mangroup
Mangroup dtale
Weaknesses CWE-310
CWE-330
CPEs cpe:2.3:a:mangroup:dtale:*:*:*:*:*:*:*:*
Vendors & Products Mangroup
Mangroup dtale
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-15T14:15:08.291Z

Reserved: 2026-08-14T18:57:25.195Z

Link: CVE-2026-19896

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T15:16:37.507

Modified: 2026-08-15T15:16:37.507

Link: CVE-2026-19896

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses