Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2957
  • PyPI/prefect
Prefect has an Argument Injection issue 13 Jul
  • No fix available
  • Severity - 8.5 (High)
PYSEC-2026-2955
  • PyPI/prefect
Prefect Git Argument Injection in GitRepository Pull Steps 13 Jul
  • Fix available
  • Severity - 2.1 (Low)
PYSEC-2026-2956
  • PyPI/prefect
Prefect Auth Bypass via endswith() Health Check Exemption 13 Jul
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-2959
  • PyPI/prefect
Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url 13 Jul
  • Fix available
  • Severity - 1.3 (Low)
PYSEC-2026-2958
  • PyPI/prefect
Prefect Unauthenticated Event Injection via /api/events/in WebSocket 13 Jul
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-1800
  • PyPI/prefect
Prefect CORS (Cross-Origin Resource Sharing) misconfiguration 07 Jul
  • Fix available
  • Severity - 7.6 (High)
PYSEC-2026-1799
  • PyPI/prefect
Cross-Site Request Forgery vulnerability in Prefect 07 Jul
  • Fix available
  • Severity - 8.8 (High)
GHSA-c635-393c-hcx2
  • PyPI/prefect
Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready' 02 Jun
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-2261
  • PyPI/prefect
See record for full details 02 Jun
  • Fix available
  • Severity - 7.5 (High)
GHSA-cw25-2p92-7f75
  • PyPI/prefect
Prefect has an Argument Injection issue 26 May
  • No fix available
  • Severity - 8.5 (High)
GHSA-6rcx-55r6-jx65
  • PyPI/prefect
Prefect Git Argument Injection in GitRepository Pull Steps 04 May
  • Fix available
  • Severity - 2.1 (Low)
GHSA-6rr6-v7cj-mxpg
  • PyPI/prefect
Prefect Auth Bypass via endswith() Health Check Exemption 04 May
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-hvph-5985-r63v
  • PyPI/prefect
Prefect Unauthenticated Event Injection via /api/events/in WebSocket 04 May
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-p3pq-hxmr-vqqr
  • PyPI/prefect
Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url 04 May
  • Fix available
  • Severity - 1.3 (Low)
GHSA-4v9f-r55g-g6hc
  • PyPI/prefect
Prefect CORS (Cross-Origin Resource Sharing) misconfiguration 20 Mar 2025
  • Fix available
  • Severity - 7.6 (High)
GHSA-4hh5-2678-83fx
  • PyPI/prefect
Cross-Site Request Forgery vulnerability in Prefect 16 Nov 2023
  • Fix available
  • Severity - 8.8 (High)