Flask security incidents

Recent advisories touching Flask apps — searchable, enriched with exploit probability and affected versions.

UNKNOWNPyPI

Malicious code in flask-header-guard (PyPI)

Malicious code in flask-header-guard (PyPI)

2 weeks ago
MODERATEPyPI

Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion

Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion

flask-security-too: ≥ 5.8.0

2 months ago
CRITICALPyPI

pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509)

pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509)

pyload-ng: all versions

5 months ago
LOWPyPI

Flask session does not add `Vary: Cookie` header when accessed in some ways

Flask session does not add `Vary: Cookie` header when accessed in some ways

flask: before 3.1.3

6 months ago
HIGHPyPI

Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods

Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods

flask-appbuilder: before 4.8.1

1 year ago
MEDIUMPyPI

Flask-AppBuilder open redirect vulnerability using HTTP host injection

Flask-AppBuilder open redirect vulnerability using HTTP host injection

flask-appbuilder: before 4.6.2

1 year ago
LOWPyPI

Flask uses fallback key instead of current signing key

Flask uses fallback key instead of current signing key

flask: 3.1.0 → 3.1.1

1 year ago
MEDIUMPyPI

Flask-CORS allows for inconsistent CORS matching

Flask-CORS allows for inconsistent CORS matching

flask-cors: before 6.0.0

1 year ago
HIGHPyPI

Flask-CORS vulnerable to Improper Handling of Case Sensitivity

Flask-CORS vulnerable to Improper Handling of Case Sensitivity

flask-cors: before 6.0.0

1 year ago
MEDIUMPyPI

Flask-CORS improper regex path matching vulnerability

Flask-CORS improper regex path matching vulnerability

flask-cors: before 6.0.0

1 year ago
MEDIUMPyPI

Flask-AppBuilder Observable Response Discrepancy

Flask-AppBuilder Observable Response Discrepancy

flask-appbuilder: before 4.5.3

1 year ago
MEDIUMPyPI

Flask-AppBuilder's login form allows browser to cache sensitive fields

Flask-AppBuilder's login form allows browser to cache sensitive fields

flask-appbuilder: before 4.5.1

2 years ago
HIGHPyPI

Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default

Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default

flask-cors: before 4.0.2

2 years ago
MEDIUMPyPI

flask-cors vulnerable to log injection when the log level is set to debug

flask-cors vulnerable to log injection when the log level is set to debug

flask-cors: before 4.0.1

2 years ago
HIGHPyPI

Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID

Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID

flask-appbuilder: before 4.3.11

2 years ago
MEDIUMPyPI

Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)

Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)

flask-appbuilder: 4.1.4 → 4.2.1

2 years ago
HIGHPyPI

pyload Unauthenticated Flask Configuration Leakage vulnerability

pyload Unauthenticated Flask Configuration Leakage vulnerability

pyload-ng: before 0.5.0b3.dev77

2 years ago
HIGHPyPI

Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header

Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header

flask: 2.3.0 → 2.3.2

3 years ago
MEDIUMPyPI

Observable Response Discrepancy in Flask-AppBuilder

Observable Response Discrepancy in Flask-AppBuilder

flask-appbuilder: before 3.4.4

4 years ago
HIGHPyPI

Flask-Cors Directory Traversal vulnerability

Flask-Cors Directory Traversal vulnerability

flask-cors: before 3.0.9

5 years ago

Tooling for Flask

SnykScan your dependencies in CI and fix this vulnerability.SocketDetect malicious and compromised packages before they ship.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.