Description
Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a replacement session token without deleting the previous token from the server-side session token store, so an old sid cookie can remain valid after logout or another renewal flow. An attacker who possesses a victim's previously valid stale cookie can replay it over HTTP or HTTPS without knowing the victim's username or password and without victim interaction at exploitation time. Successful replay can take over the victim's account, disclose private data, and permit unauthorized modification or deletion of data available to that account. This issue is fixed in version 5.0.2.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Account takeover via session replay
Action: Apply patch
AI Analysis

Impact

Hydro is a next‑generation high-performance online judge platform. From versions 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a replacement session token without deleting the previous token from the server‑side session token store, leaving an old sid cookie valid after logout or other renewal flow. An attacker with a stale cookie can replay it over HTTP or HTTPS without knowing the victim’s username or password, and without victim interaction. Successful replay permits the attacker to take over the victim’s account, disclose private data, and modify or delete data available to that account. This vulnerability is a CWE‑613 instance of insufficient session expiration.

Affected Systems

Hydro, version 4.10.4 through 5.0.2 inclusive. The issue affects the session recreation code in packages/hydrooj/src/service/layers/base.ts.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate impact. The EPSS score of <1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker must possess a stale session cookie, which can be obtained through network eavesdropping or replay, and the replay can occur remotely over HTTP or HTTPS with no victim interaction required.

Generated by OpenCVE AI on September 20, 2026 at 16:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Hydro to version 5.0.2 or later to remove old session tokens during recreation.
  • Configure the Hydro session timeout to a short period and ensure that sessions expire automatically.
  • Implement or enable server‑side session invalidation on logout or when a new token is issued, ensuring that no stale token remains in the store.

Generated by OpenCVE AI on September 20, 2026 at 16:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-94jp-7776-qj6q Hydro: Insufficient session expiration when recreating sessions
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hydro-dev
Hydro-dev hydro
Vendors & Products Hydro-dev
Hydro-dev hydro

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a replacement session token without deleting the previous token from the server-side session token store, so an old sid cookie can remain valid after logout or another renewal flow. An attacker who possesses a victim's previously valid stale cookie can replay it over HTTP or HTTPS without knowing the victim's username or password and without victim interaction at exploitation time. Successful replay can take over the victim's account, disclose private data, and permit unauthorized modification or deletion of data available to that account. This issue is fixed in version 5.0.2.
Title Hydro: Insufficient session expiration when recreating sessions
Weaknesses CWE-613
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T18:02:57.088Z

Reserved: 2026-06-16T23:31:22.446Z

Link: CVE-2026-55617

cve-icon Vulnrichment

Updated: 2026-09-15T17:38:25.251Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:18.930

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-55617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:00:13Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration