© 2025-2026 PySpect
First version without a known vulnerability: 6.0.0
Flask-CORS vulnerable to Improper Handling of Case Sensitivity
Fixed in: 6.0.0
Flask-CORS improper regex path matching vulnerability
Fixed in: 6.0.0
Flask-CORS allows for inconsistent CORS matching
Fixed in: 6.0.0
Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
Fixed in: 4.0.2
flask-cors vulnerable to log injection when the log level is set to debug
Fixed in: 4.0.1
Flask-Cors Directory Traversal vulnerability
Fixed in: 3.0.9