VDB
Sign up
HIGH7.4

GHSA-pj27-2xvp-4qxg

@fastify/session reuses destroyed session cookie

Quick fix

GHSA-pj27-2xvp-4qxg — @fastify/session: upgrade to the fixed version with the command below.

npm install @fastify/session@10.9.0

Details

### Impact

When restoring the cookie from the session store, the `expires` field is overriden if the `maxAge` field was set. This means a cookie is never correctly detected as expired and thus expired sessions are not destroyed.

### Patches

Updating to v10.9.0 will solve this.

### Workarounds

None

### References

Publicly reported at: https://github.com/fastify/session/issues/251

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@fastify/session
Introduced in: 0Fixed in: 10.9.0
Fixnpm install @fastify/session@10.9.0

References