Flask Cors Project maintains a specialized Python middleware library that handles cross-origin resource sharing (CORS) configuration for Flask web applications, a focused component that sits in the request-handling path of many web services. The library's sparse vulnerability history reflects its narrow scope and single product focus; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flask Cors Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6866HIGH corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to the use of the `try_match` function, which is originally int | Mar 20, 2025 | 7.5 | 22 | NO | NO |
CVE-2020-25032HIGH An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not | Aug 31, 2020 | 7.5 | 20 | NO | NO |
CVE-2024-6839MEDIUM corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes longer regex patterns over more specific ones when matching path | Mar 20, 2025 | 5.3 | 18 | NO | NO |
CVE-2024-6844MEDIUM A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inconsistent CORS matching due to the handling of the '+' character in URL paths. The request.path is passed thro | Mar 20, 2025 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flask Cors Project.
Media articles that mention a CVE ID that affects a product developed by Flask Cors Project — matched by CVE ID, not by vendor name.