Skip to main content

Vendor/product archive

palletsprojects / flask CVEs

Beta · best-effort

4 CVEs tagged to palletsprojects / flask0 Critical, 3 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2026-27205

Published Feb 21, 2026

Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie heade…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2023-30861

Published May 2, 2023

Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequen…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1010083

Published Jul 17, 2019

The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1