๐Ÿ” CVE Alert

CVE-2026-27205

UNKNOWN 0.0

Flask session does not add `Vary: Cookie` header when accessed in some ways

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a Use of Cache Containing Sensitive Information vulnerability. The logic instructs caches not to cache the response, as it may contain information specific to a logged in user. This is handled in most cases, but some forms of access such as the Python in operator were overlooked. The severity and risk depend on the application being hosted behind a caching proxy that doesn't ignore responses with cookies, not setting a Cache-Control header to mark pages as private or non-cacheable, and accessing the session in a way that only touches keys without reading values or mutating the session. The issue has been fixed in version 3.1.3.

CWE CWE-524
Vendor pallets
Product flask
Published Feb 21, 2026
Last Updated Feb 24, 2026
Stay Ahead of the Next One

Get instant alerts for pallets flask

Be the first to know when new unknown vulnerabilities affecting pallets flask are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

pallets / flask
< 3.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/pallets/flask/security/advisories/GHSA-68rp-wp8r-4726 github.com: https://github.com/pallets/flask/commit/089cb86dd22bff589a4eafb7ab8e42dc357623b4 github.com: https://github.com/pallets/flask/releases/tag/3.1.3