flask-security-too vulnerabilities
CVEs whose affected-version data names the flask-security-too package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
GHSA-f66q-9rf6-8795MediumFlask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
▾ Sunlitflask-security-too · flask-security-toovia OSV
CVE-2026-46715MediumFlask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
▾ Sunlitflask-security-too · flask-security-tooEPSS 0.49%via OSV