Flask-Caching through version 1.10.1 uses Python Pickle serialization for cached data. An attacker able to write a crafted serialized object into the configured cache storage can poison a cache entry. When the application deserializes that entry, attacker-controlled Python code may execute. Affected cache backends can include filesystem storage, Memcached, and Redis.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) exploit for CVE-2021-33026, targeting Flask applications that use Flask-Caching with Redis or Memcached as the backend. The exploit demonstrates a cache poisoning attack where a maliciously crafted Python pickle payload is injected into the cache (Redis or Memcached) under a specific cache key. When the vulnerable Flask application retrieves and deserializes this cache entry, it results in arbitrary command execution on the server. The repository includes: - `app.py`: A sample Flask application configured to use Redis as the cache backend, exposing several endpoints for cache manipulation and cookie handling. - `cve-2021-33026_PoC.py`: The main exploit script, which crafts and injects the malicious pickle payload into the cache and then triggers the vulnerable endpoint to execute the payload. - `readme.txt`: Instructions for setting up the environment, running the Flask app, and executing the exploit. - Requirements files for the necessary Python dependencies. The exploit requires the attacker to know a valid cache key/session ID and have access to the cache server. The main attack vector is network-based, targeting the cache backend and the Flask application's HTTP endpoints. The payload is a Python pickle object that executes arbitrary system commands when deserialized by the Flask app.
This repository contains a proof-of-concept exploit for CVE-2021-33026, a remote code execution vulnerability in Flask-Caching (<=1.10.1) when used with insecure backends like Memcached. The exploit consists of a single Python script ('cve-2021-33026_PoC.py') that crafts a malicious Pickle payload to execute arbitrary commands on the target server. The attacker must have access to the Memcached service and a valid session cookie for the vulnerable Flask application. The script connects to the target's Memcached instance (default port 11211), injects the malicious payload under the session cookie key, and then triggers deserialization by making an HTTP request to the Flask app with the poisoned session cookie. The repository also includes a README with detailed usage instructions and background information, and a standard MIT license file. The exploit demonstrates the risk of using insecure serialization (Pickle) with shared cache backends and highlights the importance of securing backend services like Memcached.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.