Intel

AIKIDO-2026-10666

prefect is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 30, 2026

70

High Risk

This Affects:

PYTHONprefect
3.0.2 - 3.6.27
Fixed in 3.6.28
Are you affected? Scan for Free

TL;DR

Affected versions of this package validate restricted outbound URLs only at pre-flight, leaving a window where the hostname can be re-resolved to a private address at connection time. An attacker-controlled DNS server can use this DNS rebinding behavior to make notification and webhook clients reach internal services.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

prefect is vulnerable to Server-Side Request Forgery (SSRF) in versions 3.0.2 - 3.6.27.

How to fix this

Upgrade the prefect library to the patch version.