CWE-565— Reliance on Cookies without Validation and Integrity Checking
The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.— MITRE CWE catalog
82 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-565page 2 of 2
- CVE-2022-28113HIGHCVSS 7.2EG 7.22022-04-15
An issue in upload.csp of FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows attackers to write files and reset the user passwords without having a valid session cookie.
- CVE-2026-39963MEDIUMCVSS 6.9EG 6.92026-04-15
Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the serendipity_setCookie() function in include/functions_config.inc.php uses $_SERVER['HTTP_HOST'] without validation as the domain parameter of setcookie(). An…
- CVE-2026-69215MEDIUMCVSS 6.8EG 6.82026-09-15
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unanchored substring checks instead of RFC 6265 domain and path matching when deciding whether to attach a stored cookie. A…
- CVE-2026-69214MEDIUMCVSS 6.8EG 6.82026-09-15
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking that it domain-matches the host that supplied the cookie or rejec…
- CVE-2017-8034MEDIUMCVSS 6.6EG 6.62017-07-17
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. Wi…
- CVE-2025-48980MEDIUMCVSS 6.5EG 6.52025-10-31
In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on …
- CVE-2024-9820MEDIUMCVSS 6.5EG 6.52024-10-15
The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-facto…
- CVE-2022-2615MEDIUMCVSS 6.5EG 6.52022-08-12
Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2021-29624MEDIUMCVSS 6.5EG 6.52021-05-19
fastify-csrf is an open-source plugin helps developers protect their Fastify server against CSRF attacks. Versions of fastify-csrf prior to 3.1.0 have a "double submit" mechanism using cookies with an application deployed across multiple s…
- CVE-2020-26955MEDIUMCVSS 6.5EG 6.52020-12-09
When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private …
- CVE-2022-1148MEDIUMCVSS 5.3EG 6.52022-04-04
Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled…
- CVE-2024-1551MEDIUMCVSS 6.1EG 6.12024-02-20
Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response head…
- CVE-2020-15128MEDIUMCVSS 6.1EG 6.12020-07-31
In OctoberCMS before version 1.0.468, encrypted cookie values were not tied to the name of the cookie the value belonged to. This meant that certain classes of attacks that took advantage of other theoretical vulnerabilities in user facing…
- CVE-2023-3747MEDIUMCVSS 5.5EG 5.52023-09-07
Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices. Override codes can also be created by the Administrators to allow a device to temporarily be disconnected from WARP, however, due to lac…
- CVE-2022-3083MEDIUMCVSS 3.9EG 5.42023-02-01
All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity. The device's web application navigation depends on the value of the session cookie. The web application could becom…
- CVE-2026-8337MEDIUMCVSS 5.3EG 5.32026-05-21
Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public and private surveys are present on the site. An unauthenticated attacker can vote in the …
- CVE-2025-31120MEDIUMCVSS 5.3EG 5.32025-04-18
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, an insecure view count mechanism in the forum page allows an unauthenticated attacker to artificially increase the view count.…
- CVE-2022-36032MEDIUMCVSS 5.3EG 5.32022-09-06
ReactPHP HTTP is a streaming HTTP client and server implementation for ReactPHP. In ReactPHP's HTTP server component versions starting with 0.7.0 and prior to 1.7.0, when ReactPHP is processing incoming HTTP cookie values, the cookie names…
- CVE-2021-3818MEDIUMCVSS 5.3EG 5.32021-09-27
grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking
- CVE-2019-4305MEDIUMCVSS 5.3EG 5.32019-09-30
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information caused by the improper setting of a cookie. IBM X-Force ID: 160951.
- CVE-2020-37007MEDIUMCVSS 4.3EG 5.32026-01-29
Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings without proper request validation. Attackers can craft malicious HTML forms to change user passwords or modify account …
- CVE-2011-3887MEDIUMCVSS v2 5.0EG 5.02011-10-25
Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors.
- CVE-2024-39734MEDIUMCVSS 4.3EG 4.32024-07-14
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting thi…
- CVE-2021-20450MEDIUMCVSS 4.3EG 4.32024-05-03
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a…
- CVE-2021-40642MEDIUMCVSS 4.3EG 4.32022-06-29
Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If …
- CVE-2020-4749MEDIUMCVSS 4.3EG 4.32020-10-20
IBM Spectrum Scale 5.0.0 through 5.0.5.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site th…
- CVE-2020-7070MEDIUMCVSS 4.3EG 4.32020-10-02
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies t…
- CVE-2019-4688MEDIUMCVSS 4.3EG 4.32020-08-26
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link i…
- CVE-2019-4330MEDIUMCVSS 4.3EG 4.32019-10-29
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session. IBM X-Force ID: 161210.
- CVE-2024-21583MEDIUMCVSS 4.1EG 4.12024-07-19
Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/components/ws-proxy/pkg/proxy before main-gha.27122; versions of the package github…
- CVE-2020-29668LOWCVSS 3.7EG 3.72020-12-10
Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
- CVE-2019-4638LOWCVSS 3.7EG 3.72020-01-28
IBM Security Secret Server 10.7 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 170044.
Map vulnerabilities like CWE-565 to your infrastructure
EchelonGraph correlates every CVE — across CWE-565 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →