Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-614 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 14 | 13 | 0 |
▂▁▁▁▁▁▁▁▁▁▂█▄▃
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 7 · 2026-07 3 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-41017 | 5.9 | 28.2 | — | Apache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-ter… |
| CVE-2026-65655 | 2.3 | 20.6 | — | Temporal UI Server may set OAuth credential cookies without Secure behind a TLS-termina… |
| CVE-2026-43828 | 5.9 | 19.7 | — | Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set… |
| CVE-2026-53661 | 8.8 | 17.8 | — | boruta-server sent sensitive session cookies without the Secure attribute |
| CVE-2025-8037 | 9.1 | 12.4 | — | Nameless cookies shadow secure cookies |
| CVE-2026-48058 | 4.6 | 9.4 | — | nebula-mesh: Session and OIDC state cookies lack the Secure attribute |
| CVE-2026-11956 | 6.3 | 9.2 | — | TwiN gatus OIDC Session Cookie oidc.go setSessionCookie missing secure attribute |
| CVE-2026-15656 | 4.3 | 8.6 | — | IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to mult… |
| CVE-2026-46398 | 8.8 | 8.2 | — | HAX CMS Missing Secure Flag on Cookie |
| CVE-2026-57948 | 7.6 | 2.7 | — | Pinpoint - Insecure Session Cookie Attributes in pinpointJwt |
| CVE-2026-56581 | 2.6 | 1.0 | — | HCL MyCloud was affected with Cookie Attribute Path Not Set |
| CVE-2026-46550 | 5.4 | 0.9 | — | NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags |
| CVE-2025-52608 | 4.3 | 0.9 | — | HCL iControl was affected by Missing Cookie Attributes vulnerability. |
| CVE-2024-23572 | 4.2 | 0.4 | — | — |
| Vendor | CVEs |
|---|---|
| apache | 2 |
| hclsoftware | 2 |
| haxtheweb | 1 |
| hcl | 1 |
| ibm | 1 |
| juev | 1 |
| malach-it | 1 |
| mozilla | 1 |
| nocodb | 1 |
| pinpoint-apm | 1 |
| temporal technologies | 1 |
| twin | 1 |