Package compatibility
Flask 3.1
What Python versions does this Flask version support?
Compatibility is derived from PyPI requires_python and Trove classifiers. CompatHub does not independently test every combination.
Declared Python requirement
- requires_python
- >=3.9
- Tip version
- 3.1.3
- Source
- PyPI (requires_python / classifiers)
Python compatibility matrix
Evaluated against CompatHub Python VersionLines. Compatibility and lifecycle status are separate signals.
- Python 2.6 line →
- Python 2.7 line →
- Python 3.0 line →
- Python 3.1 line →
- Python 3.2 line →
- Python 3.3 line →
- Python 3.4 line →
- Python 3.5 line →
- Python 3.6 line →
- Python 3.7 line →
- Python 3.8 line →
- Python 3.9 line →
- Python 3.10 line →
- Python 3.11 line →
- Python 3.12 line →
- Python 3.13 line →
- Python 3.14 line →
- Python 3.15 line →
- Python 3.16 line →
Other Flask lines
Security
Advisories affecting Flask 3.1 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 4
- Known exploited
- 0
- Highest CVSS
- —
- CVE-2025-47278PYSEC-2026-1377
Flask uses fallback key instead of current signing key
- Affected:
- >=3.1.0,<3.1.1
- Fixed in:
- 3.1.1
- Source:
- OSV source · Advisory
- CVE-2026-27205PYSEC-2026-2151
- Affected:
- <3.1.3
- Fixed in:
- 3.1.3
- Source:
- OSV source · Advisory
- CVE-2026-27205GHSA-68rp-wp8r-4726
Flask session does not add `Vary: Cookie` header when accessed in some ways
- Affected:
- <3.1.3
- Fixed in:
- 3.1.3
- Source:
- OSV source · Advisory
- CVE-2025-47278GHSA-4grg-w6v8-c28g
Flask uses fallback key instead of current signing key
- Affected:
- >=3.1.0,<3.1.1
- Fixed in:
- 3.1.1
- Source:
- OSV source · Advisory
