Threats Tagged 'cve-2026-57179'
View all threats tagged with 'cve-2026-57179'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-57179'
Click on any threat for detailed analysis and mitigation recommendations
A session fixation vulnerability (CWE-384) exists in python-social-auth's social-core component prior to version 5.0.0. The partial-pipeline resume mechanism accepted a partial token as a bearer credential without binding it to the originating browser session. This flaw could allow an attacker to initiate an authentication flow, obtain a valid partial token, and then cause a victim's browser to resume that flow, effectively authenticating the victim as the attacker. The issue affects applications using partial pipeline steps such as mail_validation or custom steps decorated with @partial. The vulnerability has been fixed in version 5.0.0 by binding partial pipeline resumes to the originating browser session. Join the discussion | CVE Database V5 | 09/24/2026, 17:27:00 UTC Added: 09/24/2026, 17:48:41 UTC |
Showing 1 to 1 of 1 result