Flask security incidents
Recent advisories touching Flask apps — searchable, enriched with exploit probability and affected versions.
Malicious code in flask-header-guard (PyPI)
Malicious code in flask-header-guard (PyPI)
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
flask-security-too: ≥ 5.8.0
pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509)
pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509)
pyload-ng: all versions
Flask session does not add `Vary: Cookie` header when accessed in some ways
Flask session does not add `Vary: Cookie` header when accessed in some ways
flask: before 3.1.3
Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods
Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods
flask-appbuilder: before 4.8.1
Flask-AppBuilder open redirect vulnerability using HTTP host injection
Flask-AppBuilder open redirect vulnerability using HTTP host injection
flask-appbuilder: before 4.6.2
Flask uses fallback key instead of current signing key
Flask uses fallback key instead of current signing key
flask: 3.1.0 → 3.1.1
Flask-CORS allows for inconsistent CORS matching
Flask-CORS allows for inconsistent CORS matching
flask-cors: before 6.0.0
Flask-CORS vulnerable to Improper Handling of Case Sensitivity
Flask-CORS vulnerable to Improper Handling of Case Sensitivity
flask-cors: before 6.0.0
Flask-CORS improper regex path matching vulnerability
Flask-CORS improper regex path matching vulnerability
flask-cors: before 6.0.0
Flask-AppBuilder Observable Response Discrepancy
Flask-AppBuilder Observable Response Discrepancy
flask-appbuilder: before 4.5.3
Flask-AppBuilder's login form allows browser to cache sensitive fields
Flask-AppBuilder's login form allows browser to cache sensitive fields
flask-appbuilder: before 4.5.1
Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
flask-cors: before 4.0.2
flask-cors vulnerable to log injection when the log level is set to debug
flask-cors vulnerable to log injection when the log level is set to debug
flask-cors: before 4.0.1
Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID
Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID
flask-appbuilder: before 4.3.11
Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)
Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)
flask-appbuilder: 4.1.4 → 4.2.1
pyload Unauthenticated Flask Configuration Leakage vulnerability
pyload Unauthenticated Flask Configuration Leakage vulnerability
pyload-ng: before 0.5.0b3.dev77
Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
flask: 2.3.0 → 2.3.2
Observable Response Discrepancy in Flask-AppBuilder
Observable Response Discrepancy in Flask-AppBuilder
flask-appbuilder: before 3.4.4
Flask-Cors Directory Traversal vulnerability
Flask-Cors Directory Traversal vulnerability
flask-cors: before 3.0.9
Tooling for Flask
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.