prefect
PyPI6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting prefectpage 1 of 1
- CVE-2023-6022HIGHCVSS 8.8EG 8.8✓ Fixed in 2.16.52023-11-16
vulnerable: 2.0.0 ... 2.9.0 (116 versions)
Cross-Site Request Forgery (CSRF) in GitHub repository prefecthq/prefect prior to 2.16.5.
- CVE-2024-8183HIGHCVSS 7.6EG 7.6✓ Fixed in 2.20.172025-03-20
vulnerable: 0.10.0 ... 2.9.0 (302 versions)
A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains to access sensitive data. This vulnerability can lead to unauthorized access to the database, resulting in potential da…
- CVE-2026-7722MEDIUMCVSS 5.3EG 5.3✓ Fixed in 3.6.222026-05-04
vulnerable: 0.10.0 ... 3.6.9 (740 versions)
A vulnerability was detected in PrefectHQ prefect up to 3.6.21. This impacts the function endswith of the file /api/health of the component Health Check API. Performing a manipulation results in improper authentication. The attack is possi…
- CVE-2026-7723HIGHCVSS 7.3EG 7.3✓ Fixed in 3.6.142026-05-04
vulnerable: 0.10.0 ... 3.6.9 (695 versions)
A flaw has been found in PrefectHQ prefect up to 3.6.13. Affected is an unknown function of the file /api/events/in of the component WebSocket Endpoint. Executing a manipulation can lead to missing authentication. The attack may be perform…
- CVE-2026-7724MEDIUMCVSS 5.0EG 5.0✓ Fixed in 3.6.28.dev22026-05-04
vulnerable: 0.10.0 ... 3.6.9 (774 versions)
A vulnerability has been found in PrefectHQ prefect up to 3.6.28.dev1. Affected by this vulnerability is the function validate_restricted_url of the component Webhook/Notification. The manipulation leads to time-of-check time-of-use. It is…
- CVE-2026-7725MEDIUMCVSS 6.3EG 6.3✓ Fixed in 3.6.25.dev72026-05-04
vulnerable: 0.10.0 ... 3.6.9 (758 versions)
A vulnerability was found in PrefectHQ prefect up to 3.6.25.dev6. Affected by this issue is some unknown functionality of the file src/prefect/runner/storage.py of the component GitRepository Pull Handler. The manipulation of the argument …
Check whether prefect is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for prefect CVEs against the assets you own.
Start Free Scan →