VYPR

PyPI package

flask

pkg:pypi/flask

Vulnerabilities (5)

  • CVE-2026-27205Feb 21, 2026
    affected < 3.1.3fixed 3.1.3

    Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a Use of Cache Containing Sensitive Information vulnerability. The logic instructs c

  • CVE-2025-47278LowMay 13, 2025
    affected >= 3.1.0, < 3.1.1fixed 3.1.1

    Flask is a web server gateway interface (WSGI) web application framework. In Flask 3.1.0, the way fallback key configuration was handled resulted in the last fallback key being used for signing, rather than the current signing key. Signing is provided by the `itsdangerous` librar

  • CVE-2023-30861May 2, 2023
    affected >= 2.3.0, < 2.3.2fixed 2.3.2

    Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by the proxy to other clients. If the proxy also caches `Set-Cookie` headers, it may send on

  • CVE-2019-1010083Jul 17, 2019
    affected < 1.0fixed 1.0

    The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.

  • CVE-2018-1000656Aug 20, 2018
    affected < 0.12.3fixed 0.12.3

    The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service. This attack appear to be exploitable via Attacker provides JSON data in incor