8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether flask is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-27205
Flask session does not add `Vary: Cookie` header when accessed in some ways
UNKNOWN
CVE-2025-47278
Flask uses fallback key instead of current signing key
HIGH 7.5
CVE-2023-30861
Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
HIGH 7.5
CVE-2018-1000656
Flask is vulnerable to Denial of Service via incorrect encoding of JSON data
HIGH 7.5
CVE-2019-1010083
Pallets Project Flask is vulnerable to Denial of Service via Unexpected memory usage
UNKNOWN
CVE-2023-30861
CVE-2023-30861
UNKNOWN
CVE-2019-1010083
CVE-2019-1010083
UNKNOWN
CVE-2018-1000656
CVE-2018-1000656
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes