CVE-2026-40939
MEDIUMDSF: Missing Session Timeout for OIDC Sessions
Title source: cnaDescription
The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity timeout. Sessions persisted indefinitely after login, even after the OIDC access token expired. This vulnerability is fixed in 2.1.0.
Scores
CVSS v4
6.8
EPSS
0.0002
EPSS Percentile
4.3%
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Details
CWE
CWE-613
Status
published
Products (4)
datasharingframework/dsf
< 2.1.0
dev.dsf/dsf-bpe-server
< 2.1.0
dev.dsf/dsf-common-jetty
< 2.1.0
dev.dsf/dsf-fhir-server
< 2.1.0
Published
Apr 21, 2026
Tracked Since
Apr 22, 2026