Prefect security advisories
8 advisories across Prefect
| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 2 | Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready' CVE-2026-3514High7.5fixed in 3.6.22.dev7 | High7.5 | 3.6.22.dev7 |
| May 26 | Prefect has an Argument Injection issue CVE-2026-3515High8.5no fix yet | High8.5 | No fix yet |
| May 4 | Prefect Git Argument Injection in GitRepository Pull Steps CVE-2026-7725Low6.3fixed in 3.6.25.dev7 | Low6.3 | 3.6.25.dev7 |
| May 4 | Prefect Auth Bypass via endswith() Health Check Exemption CVE-2026-7722Medium5.3fixed in 3.6.22 | Medium5.3 | 3.6.22 |
| May 4 | Prefect Unauthenticated Event Injection via /api/events/in WebSocket CVE-2026-7723Medium7.3fixed in 3.6.14 | Medium7.3 | 3.6.14 |
| May 4 | Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url CVE-2026-7724Low5.0fixed in 3.6.28.dev2 | Low5.0 | 3.6.28.dev2 |
| Mar 202025 | Prefect CORS (Cross-Origin Resource Sharing) misconfiguration CVE-2024-8183High7.6fixed in 2.20.17, 3.0.3 | High7.6 | 2.20.17, 3.0.3 |
| Nov 162023 | Cross-Site Request Forgery vulnerability in Prefect CVE-2023-6022High8.8fixed in 2.16.5 | High8.8 | 2.16.5 |