Flask Web Application Framework Vulnerability in Key Configuration
CVE-2025-47278
What is CVE-2025-47278?
A vulnerability in Flask 3.1.0 concerns the mishandling of key configuration for signing sessions. When utilizing key rotation via the SECRET_KEY_FALLBACKS setting, Flask improperly assembles the list of signing keys, leading to the last key in the list being used erroneously. This misconfiguration can result in sessions being signed with outdated keys, complicating transitions to newer keys. Although sessions remain signed and there’s no risk of data integrity loss, it is imperative for users to upgrade to Flask version 3.1.1, which addresses this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
flask = 3.1.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
