Skip to content
PrefectGHSA-hvph-5985-r63v

Prefect Unauthenticated Event Injection via /api/events/in WebSocket

Medium7.3CVE-2026-7723 · Published May 4, 2026 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
prefect
PyPI
< 3.6.143.6.14
Details and references

A flaw has been found in PrefectHQ prefect up to 3.6.13. Affected is an unknown function of the file /api/events/in of the component WebSocket Endpoint. Executing a manipulation can lead to missing authentication. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version 3.6.14 is able to address this issue. This patch is called 0d3ab3c2d3f9f98abfafdf7b9f6d4f8ed3925e40. It is recommended to upgrade the affected component.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-287
Also known as
CVE-2026-7723, PYSEC-2026-2958

More Prefect advisories

All Prefect
DateAdvisory
May 4Prefect Auth Bypass via endswith() Health Check Exemption
CVE-2026-7722Medium5.3fixed in 3.6.22
May 4Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url
CVE-2026-7724Low5.0fixed in 3.6.28.dev2
May 4Prefect Git Argument Injection in GitRepository Pull Steps
CVE-2026-7725Low6.3fixed in 3.6.25.dev7
May 26Prefect has an Argument Injection issue
CVE-2026-3515High8.5no fix yet
Jun 2Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'
CVE-2026-3514High7.5fixed in 3.6.22.dev7
Mar 202025Prefect CORS (Cross-Origin Resource Sharing) misconfiguration
CVE-2024-8183High7.6fixed in 2.20.17, 3.0.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.