prefect has 8 CVEs on record between 2023 and 2026. Disclosures have slowed: 0 in the last 90 days after 6 in the 90 before. The busiest recent month was May 2026 with 5. The median CVSS is 7.4 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.4
- Publish → KEV
- —
- Last 90 days
- 0 prev 6
Products
- prefect 8
Worst active — by depth score
CVE-2023-6022High· 8.8Cross-Site Request Forgery vulnerability in Prefect48CVE-2026-3515High· 8.5Prefect has an Argument Injection issue47CVE-2024-8183High· 7.6Prefect CORS (Cross-Origin Resource Sharing) misconfiguration42CVE-2026-3514High· 7.5Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'41CVE-2026-7723High· 7.3Prefect Unauthenticated Event Injection via /api/events/in WebSocket40
prefect vulnerabilities
CVEs affecting prefect, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-3514High· 7.5Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'
Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'
CVE-2026-3515High· 8.5Prefect has an Argument Injection issue
Prefect has an Argument Injection issue
CVE-2026-7724Medium· 5.0Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url
Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url
CVE-2026-7723High· 7.3Prefect Unauthenticated Event Injection via /api/events/in WebSocket
Prefect Unauthenticated Event Injection via /api/events/in WebSocket
CVE-2026-7722Medium· 5.3Prefect Auth Bypass via endswith() Health Check Exemption
Prefect Auth Bypass via endswith() Health Check Exemption
CVE-2026-7725Medium· 6.3Prefect Git Argument Injection in GitRepository Pull Steps
Prefect Git Argument Injection in GitRepository Pull Steps
CVE-2024-8183High· 7.6Prefect CORS (Cross-Origin Resource Sharing) misconfiguration
Prefect CORS (Cross-Origin Resource Sharing) misconfiguration
CVE-2023-6022High· 8.8Cross-Site Request Forgery vulnerability in Prefect
Cross-Site Request Forgery vulnerability in Prefect