This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryFixed CWE-384 Session Fixation by rotating session IDs on login.
Full changelog
Release song: https://youtu.be/QcJj9lBqjuY
tirreno is thrilled to announce v0.10.0!
This release has been in development for five months and marks a significant
shift for the tirreno framework. It introduces a new API that will help
developers and coding agents build new sections and pages, creating security
systems tailored to their own products' needs. Moreover, it includes new RBAC
and system operators to do this in an efficient and secure way.
On a separate note, the tirreno team would like to thank the publisher, and
personally Markus Stubbig from iX magazine, for the article and for featuring
tirreno on the front page of the July 2026 issue. Thank you for having us.
Link to the article: https://www.heise.de/select/ix/2026/7/2604013251085560826
Finally, we would like to thank cybersecurity researcher Pranav Pandit for
his report regarding CWE-384: Session Fixation, which affected tirreno
in that the session ID was not rotated after a user logged in. This issue has
been resolved and a patch is included in this release.
Security Fixes
- CVE-2026-???? — Session Fixation (CWE-384): session ID now rotates after user login
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About tirreno
tirreno is an open-source security framework. Event tracking, threat detection, and risk scoring for any application.
Related context
Related tools
Beta — feedback welcome: [email protected]