{"id":"CVE-2026-40939","summary":"DSF: Missing Session Timeout for OIDC Sessions","details":"The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity timeout. Sessions persisted indefinitely after login, even after the OIDC access token expired. This vulnerability is fixed in 2.1.0.","aliases":["GHSA-gj7p-595x-qwf5"],"modified":"2026-08-12T16:24:09.549677Z","published":"2026-04-21T21:07:10.503Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-613"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40939.json"},"references":[{"type":"WEB","url":"https://dsf.dev/operations/v2.1.0/bpe/oidc.html"},{"type":"WEB","url":"https://dsf.dev/operations/v2.1.0/fhir/oidc.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40939.json"},{"type":"ADVISORY","url":"https://github.com/datasharingframework/dsf/security/advisories/GHSA-gj7p-595x-qwf5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40939"},{"type":"FIX","url":"https://github.com/datasharingframework/dsf/commit/f4ecb002f7d12642f92da6b79371ed367d0140e7"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/datasharingframework/dsf","events":[{"introduced":"0"},{"fixed":"f4ecb002f7d12642f92da6b79371ed367d0140e7"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.1.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40939.json","vanir_signatures_modified":"2026-08-12T16:24:09Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"210181381239785066909336978145319676186","length":2038},"id":"CVE-2026-40939-5e26d866","signature_type":"Function","signature_version":"v1","source":"https://github.com/datasharingframework/dsf/commit/f4ecb002f7d12642f92da6b79371ed367d0140e7","target":{"function":"configureSecurityHandler","file":"dsf-common/dsf-common-jetty/src/main/java/dev/dsf/common/config/AbstractJettyConfig.java"}},{"deprecated":false,"digest":{"line_hashes":["248096590266952299710677370088390545953","146475039690892316880230810956092598626","41711526200985995544726817975565267409","256734907175591921625418883971013261991","12046530766255497784204770756465695409","332040351619878257289569583339656115118","260544613540510505523709440821166660461","288894658328232074037470236494617495402","30703326167204458460381198951915835357","227076366804677283762638055540392050621","246656753385855507859373074942442585613","213377710762040706321652335220487382147","231593500582883559640920612876790959081","11411559198146165848917718123426585635","258436804150374241867369851500833160165","227691774621626500671257398890921866664","46214790466263879217428108970028808461","156026455150512618786783065140695801491","302937849087078487730907329418466592094","189889298203746964346111955809768545321","116484648289259667242044494192994718732","57117024625802663270621038306793351462","103529135548611454831188296160855468181","287755653092785642344714559979170487564","65819801481557708647655506688433900671","149006603760383720247320303193345520848"],"threshold":0.9},"id":"CVE-2026-40939-82915cf7","signature_type":"Line","signature_version":"v1","source":"https://github.com/datasharingframework/dsf/commit/f4ecb002f7d12642f92da6b79371ed367d0140e7","target":{"file":"dsf-common/dsf-common-jetty/src/main/java/dev/dsf/common/config/AbstractJettyConfig.java"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}