Flask
Vendor:
First CVE: Aug 20, 2018 · Active for 7 years
4
Total CVEs
More Total CVEs than 72% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Flask over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 20, 2018
7 years ago
Most Recent CVE
Feb 21, 2026
154 days ago
CVE Severity & Scoring
Flask4 CVEs
25%
75%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (75.0%)
Unknown0 (0.0%)
Required1 (25.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000656HIGH The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading | Aug 20, 2018 | 7.5 | 26 | NO | NO |
CVE-2023-30861HIGH Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequent | May 2, 2023 | 7.5 | 25 | NO | NO |
CVE-2019-1010083HIGH The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version i | Jul 17, 2019 | 7.5 | 23 | NO | NO |
CVE-2026-27205MEDIUM Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header | Feb 21, 2026 | 4.3 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Flask
Top CWEs
Versions
No cataloged versions.