What is CVE-2026-19896?
This CVE identifies a vulnerability in mangroup dtale up to version 3.22.0, where the `build_secret_key` function in `dtale/app.py` generates insufficiently random values for Flask Session Cookies. This flaw allows remote exploitation. Users are advised to update to the latest version.
Azərbaycanca: Bu CVE, mangroup dtale proqramının 3.22.0 versiyasına qədər olan versiyalarında Flask Session Cookie komponentində `build_secret_key` funksiyasında kifayət qədər təsadüfi olmayan dəyərlər zəifliyidir. Bu, uzaqdan istismara imkan verir. İstifadəçilərə proqramı ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which versions of mangroup dtale are affected by CVE-2026-19896?
This vulnerability affects all versions of mangroup dtale up to version 3.22.0.
What action is recommended to mitigate CVE-2026-19896?
Users are advised to update mangroup dtale to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.