← Vulnerability feed

Vulnerability record · CVE-2018-1000656 · published 20 August 2018

CVE-2018-1000656: Palletsprojects flask improper input validation vulnerability

PPalletsprojects · Flask

The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service. This attack appear to be exploitable via Attacker provides JSON data in incorrect encoding. This vulnerability appears to have been fixed in 0.12.3. NOTE: this may overlap CVE-2019-1010083.

7.5 CVSS 3.0 High EPSS 3.9% · top 10.2% CWE-20 · Improper input validation
7.5CVSS 3.0 base score, v2 5.0
3.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service. This attack appear to be exploitable via Attacker provides JSON data in incorrect encoding. This vulnerability appears to have been fixed in 0.12.3. NOTE: this may overlap CVE-2019-1010083.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-1000656 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-12538Eclipse jetty vulnerabilityIn Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession deta…EPSS 2.7%8.1CVE-2019-3462Debian advanced package tool vulnerabilityIncorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM att…EPSS 15%7.5CVE-2023-30861Palletsprojects flask vulnerabilityFlask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one clie…EPSS 1.3%7.5CVE-2022-24785Momentjs moment path traversal vulnerabilityMoment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (serve…EPSS 14%7.5CVE-2019-1010083Palletsprojects flask vulnerabilityThe Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded…EPSS 1.9%7.5CVE-2018-18066Net-snmp null pointer dereference vulnerabilitysnmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to rem…EPSS 3.6%7.0CVE-2019-11486Linux kernel race condition vulnerabilityThe Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions.EPSS 0.37%6.5CVE-2018-18065Net-snmp null pointer dereference vulnerability_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to …EPSS 18%

Source: NIST National Vulnerability Database (record CVE-2018-1000656), CISA KEV, FIRST EPSS (scores of 2026-09-30). This page is refreshed as NVD updates the record.