Palletsprojects
Palletsprojects Flask: vulnerabilidades y CVE
Palletsprojects Flask tiene 13 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses7
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-54567 | Alta (7.5) | 0.63% | — | 14 sept 2026 | Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the… |
| CVE-2026-78553 | Alta (7) | 0.19% | — | 24 ago 2026 | RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key file was created using the process's default permissions and umask, resulting in permissions such as… |
| CVE-2026-48508 | Alta (8.8) | 0.33% | — | 18 ago 2026 | Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_principal.Permission.__init__() with zero Need objects when… |
| CVE-2026-75529 | Media (6.9) | 0.44% | — | 17 ago 2026 | Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality. The /task-download/<task_id>/.../pdf endpoint verifies that the submitted file is a PDF using Pandora's content-based… |
| CVE-2026-41522 | Alta (7.1) | 0.38% | — | 4 jun 2026 | Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to version 2.4.28, DFIR-IRIS exposes an optional GraphQL endpoint at `/graphql` that does not… |
| CVE-2026-5321 | Baja (2.1) | 0.19% | — | 2 abr 2026 | A flaw has been found in vanna-ai vanna up to 2.0.2. Affected by this issue is some unknown functionality of the component FastAPI/Flask Server. Executing a manipulation can lead to permissive cross-domain policy with… |
| CVE-2026-27205 | Baja (2.3) | 0.42% | — | 21 feb 2026 | Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a Use of Cache… |
| CVE-2025-47278 | Baja (1.8) | 0.18% | — | 13 may 2025 | Flask is a web server gateway interface (WSGI) web application framework. In Flask 3.1.0, the way fallback key configuration was handled resulted in the last fallback key being used for signing, rather than the current… |
| CVE-2024-8055 | Alta (7.5) | 0.65% | — | 20 mar 2025 | Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations using the `PUT` and `COPY` commands. This vulnerability allows unauthenticated remote users to read arbitrary local files… |
| CVE-2024-5827 | Crítica (9.8) | 3.4% | — | 28 jun 2024 | Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can inject malicious SQL training data and generate corresponding queries to write arbitrary files on the… |
| CVE-2023-30861 | Alta (7.5) | 1.3% | — | 2 may 2023 | Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by the proxy to other clients.… |
| CVE-2019-1010083 | Alta (7.5) | 1.9% | — | 17 jul 2019 | The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap… |
| CVE-2018-1000656 | Alta (7.5) | 3.9% | — | 20 ago 2018 | The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service. This attack… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.