Use of cache containing sensitive information in Flask - CVE-2026-27205
Published: April 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to when the session object is accessed, Flask should set the Vary: Cookie header. The logic instructs caches not to cache the response, as it may contain information specific to a logged in user. This is handled in most cases, but some forms of access such as the Python in operator were overlooked. The severity and risk depend on the application being hosted behind a caching proxy that doesn't ignore responses with cookies, not setting a Cache-Control header to mark pages as private or non-cacheable, and accessing the session in a way that only touches keys without reading values or mutating the session. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Python 3 Module
openSUSE Leap
Ubuntu
openEuler
IBM Cloud Pak for Data System
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Maximo Application Suite
IBM Cloud Object Storage Systems
Maximo Application Suite - IoT Component
Maximo Application Suite - Visual Inspection Component
Maximo Application Suite Ai Service
Maximo Scheduler Optimizer
Storage Protect Plus Server
IBM InfoSphere Information Server
flask (Ubuntu package)
python3-flask
python-flask
python311-Flask
python311-Flask-doc
How to mitigate CVE-2026-27205
IBM Cloud Pak for Data System - update to 8.10.26.06.SP2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
Maximo Application Suite - IoT Component - addressed in versions 8.7.32, 8.8.29, 9.0.18, 9.1.9
Maximo Application Suite - Visual Inspection Component - addressed in versions 8.9.21, 9.0.19, 9.1.12
IBM Maximo Application Suite - addressed in versions 8.10.36, 8.11.33, 9.0.22, 9.1.11
Maximo Application Suite Ai Service - update to 9.1.13
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
flask (Ubuntu package) - addressed in versions 1.1.1-2ubuntu0.1+esm1, 2.0.1-2ubuntu1.2, 3.0.2-1ubuntu1.1
python3-flask - update to 2.2.5-2
python-flask - update to 2.2.5-2
python311-Flask - update to 2.3.2-150400.3.9.1
python311-Flask-doc - update to 2.3.2-150400.3.9.1
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.43, 3.20.0.69
Maximo Scheduler Optimizer - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
Storage Protect Plus Server - update to 10.1.18
External References
Related Security Bulletins
- Use of cache containing sensitive information in Flask
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Multiple vulnerabilities in IBM Storage Protect Plus Server
- SUSE update for python-Flask
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Maximo AI Service
- Ubuntu update for flask
- openEuler 24.03 LTS SP1 update for python-flask
- openEuler 24.03 LTS update for python-flask
- openEuler 24.03 LTS SP3 update for python-flask
- IBM Maximo Application Suite - Visual Inspection Component update for Flask
- IBM Maximo Scheduler Optimizer update for Flask
- Multiple vulnerabilities in IBM Cloud Object System
- IBM Watson Discovery Cartridge update for Flask
- IBM Watson Speech Services Cartridge update for Flask
- IBM InfoSphere Information Server update for Flask
- IBM Cloud Pak for Data System update for Flask