Session Token Vulnerability in Hydro Online Judge Platform
CVE-2026-55617

6.9MEDIUM

Key Information:

Vendor

Hydro-dev

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-55617?

The Hydro Online Judge Platform presents a session token vulnerability affecting versions 4.10.4 through 5.0.2. This issue arises from the server's failure to delete old session tokens during the recreation process. As a result, stale session cookies can remain valid even after a user has logged out or refreshed their session. An attacker with access to a valid stale cookie can exploit this flaw to perform actions on behalf of the victim without requiring their credentials or interaction. Such a vulnerability risks unauthorized access to sensitive information and privileged actions on the user's account. The issue was addressed in version 5.0.2.

Affected Version(s)

Hydro >= 4.10.4, < 5.0.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.