A high-severity flaw tracked as CVE-2026-53661 affected Boruta, a standalone OAuth 2.0 and OpenID Connect authorization server, by issuing session cookies and the identity remember me cookie without the Secure attribute. In affected deployments, browsers could send those cookies over plaintext HTTP, creating a risk that attackers monitoring or intercepting traffic could steal valid cookies and hijack authenticated sessions, including administrative sessions. The issue impacted all released versions through 0.9.0 and unreleased builds before commit 18691c655164635066aa113003a3cd87f6ed11cd, with affected components including boruta_web, boruta_identity, and boruta_admin and default cookies such as _boruta_web_key and _boruta_identity_web_user_remember_me.
The project addressed the flaw in commit 18691c655164635066aa113003a3cd87f6ed11cd, which enforces secure cookie handling across Boruta endpoints, adds SameSite=Lax to configured session cookies, and updates the remember-me cookie to require HTTPS transport. The fix was subsequently released in version 0.9.1. Maintainers advised operators to enforce HTTPS-only access, reject plaintext HTTP, enable HSTS, verify that cookies are deployed with the Secure attribute, and rotate secrets such as SECRET_KEY_BASE and BORUTA_SESSION_COOKIE_SIGNING_SALT if cookie exposure is suspected.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2026-53661 reported that Boruta's insecure cookie handling issue was fixed in commit 18691c655164635066aa113003a3cd87f6ed11cd and released in version 0.9.1. It described exposure of session and remember-me cookies without the Secure attribute across boruta_web, boruta_identity, and boruta_admin.
A GitHub security advisory disclosed that all released Boruta versions through 0.9.0 set session and remember-me cookies without the Secure attribute, enabling possible session hijacking if traffic was intercepted over HTTP. The advisory stated the fix was available in commit 18691c655164635066aa113003a3cd87f6ed11cd, but that no tagged release yet contained the patch.
A security commit updated BorutaAdminWeb, BorutaIdentityWeb, and BorutaWeb to set the Secure flag and SameSite=Lax on session cookies, and added the Secure flag to the remember-me cookie configuration. This change mitigated the risk of cookies being transmitted over plaintext HTTP.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.