github.com/pallets/flask
Submitted 7/28/2026, 7:55:57 PM · Status: ok
Risk grade
F
100 / 100
Findings
138
0 critical10 high123 medium3 low2 info0 on CISA KEV0ATT&CK
Showing 138 of 138 findings
Findings
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoSgrypeCVE-2026-54283EPSS 0.3%
- Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on WindowsgrypeCVE-2026-48818EPSS 0.4%
- Vulnerable OpenSSL included in cryptography wheelsgrype
- Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domaingrypeCVE-2024-34069EPSS 3.4%
- python-werkzeug: user may execute code on a developer's machineWerkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some circumstances. This requires the attacker to get the developer to interact with a domain and subdomain…trivyCVE-2024-34069
This report is public.