prefect is vulnerable to Regular Expression Denial of Service (ReDoS)
52
Medium Risk
Due to a vulnerability in the starlette package (CVE-2024-24762) and the inability of Prefect to update to a fixed version, parts of the package were rewritten to eliminate the vulnerability. Affected versions of this package are susceptible to regular expression Denial of Service (ReDoS) in python-multipart.
You are affected if you are using a version that falls within the vulnerable range.
prefect is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 2.14.0 - 2.14.21.
Upgrade the prefect library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant