Unknown · Treefrog-Framework · CVE-2026-19974
**Name of the Vulnerable Software and Affected Versions**
treefrog-framework versions prior to 2.11.3
**Description**
A flaw in the Session Cookie Handler component allows for improper authentication via remote manipulation. The issue resides in the `std::strncmp()` function within the `src/tsessioncookiestore.cpp` file. This attack is characterized by high complexity and difficult exploitability.
**Recommendations**
Update treefrog-framework to a version newer than 2.11.2.
As a temporary mitigation, restrict access to the Session Cookie Handler component to minimize the risk of exploitation.