VulnSea

prefect has 8 CVEs on record between 2023 and 2026. Disclosures have slowed: 0 in the last 90 days after 6 in the 90 before. The busiest recent month was May 2026 with 5. The median CVSS is 7.4 (high). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.4
Publish → KEV
Last 90 days
0 prev 6

Products

  • prefect 8
8
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

prefect vulnerabilities

CVEs affecting prefect, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-3514High· 7.5
3mo ago

Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'

Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'

Twilightprefect · prefectEPSS 0.48%via OSV
CVE-2026-3515High· 8.5
3mo ago

Prefect has an Argument Injection issue

Prefect has an Argument Injection issue

Twilightprefect · prefectEPSS 0.30%via OSV
CVE-2026-7724Medium· 5.0
4mo ago

Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url

Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url

Sunlitprefect · prefectEPSS 0.25%via OSV
CVE-2026-7723High· 7.3
4mo ago

Prefect Unauthenticated Event Injection via /api/events/in WebSocket

Prefect Unauthenticated Event Injection via /api/events/in WebSocket

Twilightprefect · prefectEPSS 0.42%via OSV
CVE-2026-7722Medium· 5.3
4mo ago

Prefect Auth Bypass via endswith() Health Check Exemption

Prefect Auth Bypass via endswith() Health Check Exemption

Sunlitprefect · prefectEPSS 0.45%via OSV
CVE-2026-7725Medium· 6.3
4mo ago

Prefect Git Argument Injection in GitRepository Pull Steps

Prefect Git Argument Injection in GitRepository Pull Steps

Sunlitprefect · prefectEPSS 0.25%via OSV
CVE-2024-8183High· 7.6
1y ago

Prefect CORS (Cross-Origin Resource Sharing) misconfiguration

Prefect CORS (Cross-Origin Resource Sharing) misconfiguration

Twilightprefect · prefectEPSS 0.18%via OSV
CVE-2023-6022High· 8.8
2y ago

Cross-Site Request Forgery vulnerability in Prefect

Cross-Site Request Forgery vulnerability in Prefect

Twilightprefect · prefectEPSS 0.39%via OSV
prefect vulnerabilities (CVEs) · VulnSea