aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and NaClCookieStorage that can result in Non-expiring sessions / Infinite lifespan. This attack appear to be exploitable via Recreation of a cookie post-expiry with the same value.
{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.6.0"
}
],
"cpe": "cpe:2.3:a:aio-libs:aiohttp_session:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD"
}