© 2025-2026 PySpect
First version without a known vulnerability: 3.1.3
Flask session does not add `Vary: Cookie` header when accessed in some ways
Fixed in: 3.1.3
Flask uses fallback key instead of current signing key
Fixed in: 3.1.1
Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
Fixed in: 2.3.2, 2.2.5, 70f906c51ce49c485f1d355703e9cc3386b1cc2b, afd63b16170b7c047f5758eb910c416511e9c965
Pallets Project Flask is vulnerable to Denial of Service via Unexpected memory usage
Fixed in: 1.0
Flask is vulnerable to Denial of Service via incorrect encoding of JSON data
Fixed in: 0.12.3