CVE-2025-47278 affects Flask 3.1.0, where a flaw in key rotation logic causes sessions to be signed with stale keys instead of the intended current key when SECRET_KEY_FALLBACKS is enabled. This issue, while not leading to data integrity loss, impedes the proper transition to fresher keys. With a CVSS score of 1.8 (LOW), the vulnerability has a local attack vector and high privileges are required for exploitation. There is no known active exploitation, public exploit code, or KEV listing, though it has garnered minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Pallets | Flask | = 3.1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.