Use of Cache Containing Sensitive Information in Flask
CVE-2026-27205
- Flask
Summary
Flask is a web server gateway interface (WSGI) web application framework. In versions through 3.1.2, when the session object is accessed, Flask should set the Vary: Cookie header, resulting in a Use of Cache Containing Sensitive Information vulnerability. The logic instructs caches not to cache the response, as it may contain information specific to a logged-in user. This is handled in most cases, but some forms of access such as the Python in operator were overlooked. The severity and risk depend on the application being hosted behind a caching proxy that doesn't ignore responses with cookies, not setting a Cache-Control header to mark pages as private or non-cacheable, and accessing the session in a way that only touches keys without reading values or mutating the session. The issue has been fixed in version 3.1.3.
- LOW
- NETWORK
- NONE
- UNCHANGED
- REQUIRED
- NONE
- LOW
- NONE
CWE-524 - Use of Cache Containing Sensitive Information
The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
References
Advisory Timeline
- Published