VulnSea

prefect vulnerabilities

CVEs whose affected-version data names the prefect package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

8 CVEsRSS

CVE-2026-3514High· 7.5
3mo ago

Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'

Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'

Twilightprefect · prefectEPSS 0.48%via OSV
CVE-2026-3515High· 8.5
3mo ago

Prefect has an Argument Injection issue

Prefect has an Argument Injection issue

Twilightprefect · prefectEPSS 0.30%via OSV
CVE-2026-7724Medium· 5.0
4mo ago

Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url

Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url

Sunlitprefect · prefectEPSS 0.25%via OSV
CVE-2026-7723High· 7.3
4mo ago

Prefect Unauthenticated Event Injection via /api/events/in WebSocket

Prefect Unauthenticated Event Injection via /api/events/in WebSocket

Twilightprefect · prefectEPSS 0.42%via OSV
CVE-2026-7722Medium· 5.3
4mo ago

Prefect Auth Bypass via endswith() Health Check Exemption

Prefect Auth Bypass via endswith() Health Check Exemption

Sunlitprefect · prefectEPSS 0.45%via OSV
CVE-2026-7725Medium· 6.3
4mo ago

Prefect Git Argument Injection in GitRepository Pull Steps

Prefect Git Argument Injection in GitRepository Pull Steps

Sunlitprefect · prefectEPSS 0.25%via OSV
CVE-2024-8183High· 7.6
1y ago

Prefect CORS (Cross-Origin Resource Sharing) misconfiguration

Prefect CORS (Cross-Origin Resource Sharing) misconfiguration

Twilightprefect · prefectEPSS 0.18%via OSV
CVE-2023-6022High· 8.8
2y ago

Cross-Site Request Forgery vulnerability in Prefect

Cross-Site Request Forgery vulnerability in Prefect

Twilightprefect · prefectEPSS 0.39%via OSV
prefect vulnerabilities (CVEs) · VulnSea