Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-05-15
8 active CVEs reported via OSV.dev
Flask uses fallback key instead of current signing key
Flask is vulnerable to Denial of Service via incorrect encoding of JSON data
Pallets Project Flask is vulnerable to Denial of Service via Unexpected memory usage
Flask session does not add `Vary: Cookie` header when accessed in some ways
Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
Other Web Framework projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Flask โ without relying on volunteer maintainers.
Talk to an Expert โ