PyPI: flask

CVE-2019-1010083

Safety vulnerability ID: SFTY-20190717-33285

Safety legacy ID: pyup.io-38654

Flask 0.12.3 includes a fix for CVE-2019-1010083: Unexpected memory usage. The impact is denial of service. The attack vector is crafted encoded JSON data. NOTE: this may overlap CVE-2018-1000656. https://github.com/pallets/flask/pull/2695/commits/0e1e9a04aaf29ab78f721cfc79ac2a691f6e3929

Created at: Mar 4, 2026Updated at: Mar 4, 2026

Overview

Pallets Project Flask is vulnerable to Denial of Service via Unexpected memory usage

Advisory

Flask 0.12.3 includes a fix for CVE-2019-1010083: Unexpected memory usage. The impact is denial of service. The attack vector is crafted encoded JSON data. NOTE: this may overlap CVE-2018-1000656. https://github.com/pallets/flask/pull/2695/commits/0e1e9a04aaf29ab78f721cfc79ac2a691f6e3929

Affected Package

Affecting flask package, versions
<0.12.3

Also affects

---

How to Fix

Upgrade
flask
to
0.12.3
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more