CVE-2026-19896 | mangroup dtale up to 3.22.0 Flask Session Cookie dtale/app.py build_secret_key random values (Issue 960)
A vulnerability has been found in mangroup dtale up to 3.22.0 and classified as problematic. This vulnerability affects the function build_secret_key of the file dtale/app.py of the component Flask Session Cookie. This manipulation causes insufficiently random values.
This vulnerability is registered as CVE-2026-19896. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The pull request to fix this issue awaits acceptance.VulDB Recent EntriesRead More