CVE-2026-27205
CVE-2026-27205 is a medium-severity vulnerability in Palletsprojects Flask with a CVSS 3.x base score of 4.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-524.
Key facts
- Severity: Medium (CVSS 3.x base score 4.3)
- CVSS v4: 2.3
- EPSS exploit prediction: 0% (28th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-7731
- Weakness: CWE-524
- Affected product: Palletsprojects Flask
- Published:
- Last modified:
Description
Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a Use of Cache Containing Sensitive Information vulnerability. The logic instructs caches not to cache the response, as it may contain information specific to a logged in user. This is handled in most cases, but some forms of access such as the Python in operator were overlooked. The severity and risk depend on the application being hosted behind a caching proxy that doesn't ignore responses with cookies, not setting a Cache-Control header to mark pages as private or non-cacheable, and accessing the session in a way that only touches keys without reading values or mutating the session. The issue has been fixed in version 3.1.3.
Frequently asked questions
- What is CVE-2026-27205?
- Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a Use of Cache Containing Sensitive Information vulnerability. The logic instructs caches not to cache the response, as it may contain information specific to a logged in user. This is handled in most cases, but some forms of access such as the Python in operator were overlooked. The severity and risk depend on the application being hosted behind a caching proxy that doesn't ignore responses with cookies, not setting a Cache-Control header to mark pages as private or non-cacheable, and accessing the session in a way that only touches keys without reading values or mutating the session. The issue has been fixed in version 3.1.3.
- How severe is CVE-2026-27205?
- CVE-2026-27205 has a CVSS 3.x base score of 4.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2026-27205 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (28th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-27205?
- CVE-2026-27205 affects Palletsprojects Flask. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-27205?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-27205 have an EU (EUVD) identifier?
- Yes. CVE-2026-27205 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-7731.
- When was CVE-2026-27205 published?
- CVE-2026-27205 was published on 2026-02-21 and last updated on 2026-06-17.
References
- https://github.com/pallets/flask/commit/089cb86dd22bff589a4eafb7ab8e42dc357623b4
- https://github.com/pallets/flask/releases/tag/3.1.3
- https://github.com/pallets/flask/security/advisories/GHSA-68rp-wp8r-4726
Affected products (1)
- cpe:2.3:a:palletsprojects:flask:*:*:*:*:*:*:*:*
More vulnerabilities in Palletsprojects Flask
- CVE-2023-30861 — High (CVSS 7.5): Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response…
- CVE-2019-1010083 — High (CVSS 7.5): The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The…
- CVE-2018-1000656 — High (CVSS 7.5): The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask…
All CVEs affecting Palletsprojects Flask →
Other CWE-524 vulnerabilities
- CVE-2026-53943 — Critical (CVSS 9.6): Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that…
- CVE-2025-64762 — Critical (CVSS 9.1): The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS &…
- CVE-2026-61836 — High (CVSS 8.6): Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching…
- CVE-2026-71316 — High (CVSS 7.5): Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries…
- CVE-2026-65755 — High (CVSS 7.5): Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere…
- CVE-2026-64792 — High (CVSS 7.5): Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs…
Browse all CWE-524 vulnerabilities →
Threat intelligence
Threat-intel indicators referencing this CVE:
- 144.22.150.242 (ipv4-addr)
- 97.74.87.152 (ipv4-addr)
- 106.13.228.234 (ipv4-addr)
- 196.188.187.59 (ipv4-addr)
- 64.227.116.82 (ipv4-addr)
- 8.213.129.95 (ipv4-addr)
- 129.212.184.120 (ipv4-addr)
- 41.33.231.52 (ipv4-addr)