{"id":"CVE-2016-3954","aliases":["GHSA-jr83-vr4j-mp6p","PYSEC-2026-1062"],"url":"https://o3.security/vulnerability/CVE-2016-3954","summary":"web2py exposure of sensitive information","details":"web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status.  NOTE: this issue can be leveraged by remote attackers to execute arbitrary code using CVE-2016-3957.","published":"2018-02-06T18:29:00.337Z","modified":"2026-08-07T14:49:21.690535Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.01385,"percentile":0.69608,"asOf":"2026-08-09"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"web2py","fixedVersion":"2.14.2"}],"fix":null,"references":[{"type":"WEB","url":"https://usn.ubuntu.com/4030-1/"},{"type":"EVIDENCE","url":"https://devco.re/blog/2017/01/03/web2py-unserialize-code-execution-CVE-2016-3957/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:49:21.690535Z"}}