Skip to main content

Use of Cache Containing Sensitive Information in Flask

CVE-2026-27205

  • Flask
Severity Low
Score 2.3/10

Summary

Flask is a web server gateway interface (WSGI) web application framework. In versions through 3.1.2, when the session object is accessed, Flask should set the Vary: Cookie header, resulting in a Use of Cache Containing Sensitive Information vulnerability. The logic instructs caches not to cache the response, as it may contain information specific to a logged-in user. This is handled in most cases, but some forms of access such as the Python in operator were overlooked. The severity and risk depend on the application being hosted behind a caching proxy that doesn't ignore responses with cookies, not setting a Cache-Control header to mark pages as private or non-cacheable, and accessing the session in a way that only touches keys without reading values or mutating the session. The issue has been fixed in version 3.1.3.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • REQUIRED
  • NONE
  • LOW
  • NONE

CWE-524 - Use of Cache Containing Sensitive Information

The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

Advisory Timeline

  • Published