PrefectGHSA-hvph-5985-r63v
Prefect Unauthenticated Event Injection via /api/events/in WebSocket
Medium7.3CVE-2026-7723 · Published May 4, 2026 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| prefect PyPI | < 3.6.14 | 3.6.14 |
Details and references
A flaw has been found in PrefectHQ prefect up to 3.6.13. Affected is an unknown function of the file /api/events/in of the component WebSocket Endpoint. Executing a manipulation can lead to missing authentication. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version 3.6.14 is able to address this issue. This patch is called 0d3ab3c2d3f9f98abfafdf7b9f6d4f8ed3925e40. It is recommended to upgrade the affected component.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-287
- Also known as
- CVE-2026-7723, PYSEC-2026-2958
- nvd.nist.gov/vuln/detail/CVE-2026-7723
- github.com/PrefectHQ/prefect/pull/20372
- github.com/PrefectHQ/prefect/commit/0d3ab3c2d3f9f98abfafdf7b9f6d4f8ed3925e40
- github.com/PrefectHQ/prefect/commit/f8afecadf88ea5f73694dafa3a365b9d8fae1ad6
- gist.github.com/nedlir/f1ab8aa038aafbcc6beeef21fab1d74f
- github.com/PrefectHQ/prefect
- github.com/PrefectHQ/prefect/releases/tag/3.6.14
- vuldb.com/submit/807256
- vuldb.com/vuln/360899
- vuldb.com/vuln/360899/cti
More Prefect advisories
All Prefect| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 4 | Prefect Auth Bypass via endswith() Health Check Exemption CVE-2026-7722Medium5.3fixed in 3.6.22 | Medium5.3 | 3.6.22 |
| May 4 | Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url CVE-2026-7724Low5.0fixed in 3.6.28.dev2 | Low5.0 | 3.6.28.dev2 |
| May 4 | Prefect Git Argument Injection in GitRepository Pull Steps CVE-2026-7725Low6.3fixed in 3.6.25.dev7 | Low6.3 | 3.6.25.dev7 |
| May 26 | Prefect has an Argument Injection issue CVE-2026-3515High8.5no fix yet | High8.5 | No fix yet |
| Jun 2 | Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready' CVE-2026-3514High7.5fixed in 3.6.22.dev7 | High7.5 | 3.6.22.dev7 |
| Mar 202025 | Prefect CORS (Cross-Origin Resource Sharing) misconfiguration CVE-2024-8183High7.6fixed in 2.20.17, 3.0.3 | High7.6 | 2.20.17, 3.0.3 |