high
CVE-2023-30861
Flask session cookie can be cached by a proxy and served to another client (session disclosure)
- Severity
- high
- Affected product
- Flask
- Affected versions
- Flask < 2.2.5
- Fixed in
- Flask 2.2.5 / 2.3.2
- Added to NewScan
- 2026-08-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Flask from its response and reports this CVE when the detected version falls inside the affected range below.
Also affects 2.3.0-2.3.1, which the 2.2.5 boundary does not cover; a second row would be needed if 2.3.x builds are still in the wild.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →