vulnerability
Ubuntu: USN-4378-1 (CVE-2018-1000656): Flask vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:N/I:N/A:P) | Aug 20, 2018 | Jun 2, 2020 | Apr 16, 2026 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Aug 20, 2018
Added
Jun 2, 2020
Modified
Apr 16, 2026
Description
The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service. This attack appear to be exploitable via Attacker provides JSON data in incorrect encoding. This vulnerability appears to have been fixed in 0.12.3. NOTE: this may overlap CVE-2019-1010083.
Solutions
ubuntu-pro-upgrade-python-flaskubuntu-pro-upgrade-python3-flaskubuntu-upgrade-python-flaskubuntu-upgrade-python3-flask
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.