IndexedVerified
Python Web Security
Django, Flask, and FastAPI SAST rules aggregated across verified providers.
Fetch pack
greprules pack fetch python-web-security --engine opengrepcurl https://api.greprules.io/api/packs/python-web-security.tar.gz -o python-web-security.tar.gzIncluded rules
CVE-2026-82271: Fastapi Unused Auth Dependency Missing Authorization
cve-2026-82271-fastapi-unused-auth-dependency-missing-authorizationCVE-2026-72776: Fastapi Missing Auth Dependencycve-2026-72776-fastapi-missing-auth-dependencyCVE-2026-71502: Flask Jinja Missing Finalize Hookcve-2026-71502-flask-jinja-missing-finalize-hookCVE-2026-71417: Lemur Duplicate Certificate Revocation Bypasscve-2026-71417-lemur-duplicate-certificate-revocation-bypassCVE-2026-69079: Flask Unbounded Resource Consumptioncve-2026-69079-flask-unbounded-resource-consumptionCVE-2026-64619: Fastapi Spoofable Client Ipcve-2026-64619-fastapi-spoofable-client-ipCVE-2026-60112: Os Path Join Traversalcve-2026-60112-os-path-join-traversalCVE-2026-55419: Fastapi Unrestricted File Uploadcve-2026-55419-fastapi-unrestricted-file-uploadCVE-2026-45365: Fastapi Internal Auth Bypass Flag As Query Paramcve-2026-45365-fastapi-internal-auth-bypass-flag-as-query-paramCVE-2026-45315: Fastapi Fileresponse Path Route Missing Protection Headerscve-2026-45315-fastapi-fileresponse-path-route-missing-protection-headersCVE-2026-44796: Django Python Re Redoscve-2026-44796-django-python-re-redosCVE-2026-42999: Flask Dict Update Mass Assignmentcve-2026-42999-flask-dict-update-mass-assignmentCVE-2026-42864: Drf Allowany On Serializer Bound Viewcve-2026-42864-drf-allowany-on-serializer-bound-viewCVE-2026-42196: Python Pureposixpath Traversal Without Clean Namecve-2026-42196-python-pureposixpath-traversal-without-clean-nameCVE-2026-40525: Python Auth Fail Open Empty Api Keycve-2026-40525-python-auth-fail-open-empty-api-keyCVE-2026-39422: Django Response Unescaped Replace Xsscve-2026-39422-django-response-unescaped-replace-xssCVE-2026-35508: Django Safestring Unescaped Interpolationcve-2026-35508-django-safestring-unescaped-interpolationCVE-2026-35046: Django Orm Lower In Comparisoncve-2026-35046-django-orm-lower-in-comparisonCVE-2026-33212: Celery Task Pending State Missing Authorizationcve-2026-33212-celery-task-pending-state-missing-authorizationCVE-2026-33076: Python Path Traversal Fstring Host Param Unvalidatedcve-2026-33076-python-path-traversal-fstring-host-param-unvalidatedCVE-2026-33057: Python Flask Request Code Executioncve-2026-33057-python-flask-request-code-executionCVE-2026-33017: Langflow Public Build Rce Via Data Paramcve-2026-33017-langflow-public-build-rce-via-data-paramCVE-2026-25873: Python Pickle Loads On Http Request Bodycve-2026-25873-python-pickle-loads-on-http-request-bodyCVE-2026-25117: Flask Csrf Bypass With Session Authcve-2026-25117-flask-csrf-bypass-with-session-auth24 of 53 loaded