Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in treefrogframework treefrog-framework up to 2.11.2. This vulnerability affects the function std::strncmp of the file src/tsessioncookiestore.cpp of the component Session Cookie Handler. The manipulation results in improper authentication. The attack can be launched remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure. | |
| Title | treefrogframework treefrog-framework Session Cookie tsessioncookiestore.cpp strncmp improper authentication | |
| First Time appeared |
Treefrogframework
Treefrogframework treefrog-framework |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:treefrogframework:treefrog-framework:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Treefrogframework
Treefrogframework treefrog-framework |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-17T02:15:08.807Z
Reserved: 2026-08-16T08:50:31.927Z
Link: CVE-2026-19974
No data.
Status : Received
Published: 2026-08-17T03:16:49.960
Modified: 2026-08-17T03:16:49.960
Link: CVE-2026-19974
No data.
OpenCVE Enrichment
Updated: 2026-08-17T03:30:12Z