CVE-2026-27205 is a Use of Cache Containing Sensitive Information vulnerability affecting Flask versions 3.1.2 and below. It occurs when the session object is accessed in specific ways, leading to sensitive data potentially being cached by proxies if proper Cache-Control headers are not set. The vulnerability has a CVSS score of 4.3 (Medium) with a network attack vector and low impact on confidentiality. There is currently no known active exploitation, public exploit code, or KEV listing, although it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.3CPE matchmatch criteria | cpe:2.3:a:palletsprojects:flask:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
USN-8104-1: Flask vulnerability
Mar 18, 2026flask: Flask: Information disclosure via improper caching of session data
Feb 21, 2026Flask session does not add `Vary: Cookie` header when accessed in some ways
Feb 19, 2026