HIGH7.5
PYSEC-2026-1380
Flask-AppBuilder Has No Rate Limiting on Login AUTH DB
Quick fix
PYSEC-2026-1380 — flask-appbuilder: upgrade to the fixed version with the command below.
pip install --upgrade 'flask-appbuilder>=4.3.0'Details
### Impact Lack of rate limiting will allow an attacker to brute-force user credentials.
### Patches Ability to enable rate limiting on Flask-AppBuilder >= 4.3.0. Use `AUTH_RATE_LIMITED = True` and `RATELIMIT_ENABLED = True` set the limit itself by using `AUTH_RATE_LIMIT`. Will apply only to database authentication.
### Workarounds Implement rate limiting using a reverse proxy or other strategies.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/flask-appbuilder
Introduced in:
0Fixed in: 4.3.0Fix
pip install --upgrade 'flask-appbuilder>=4.3.0'References
- https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-9hcr-9hcv-x6pv[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-29005[ADVISORY]
- https://github.com/dpgaspar/Flask-AppBuilder/pull/1976[WEB]
- https://flask-limiter.readthedocs.io/en/stable/configuration.html[WEB]
- https://github.com/dpgaspar/Flask-AppBuilder[PACKAGE]
- https://github.com/dpgaspar/Flask-AppBuilder/releases/tag/v4.3.0[WEB]
- https://pypi.org/project/flask-appbuilder[PACKAGE]
- https://github.com/advisories/GHSA-9hcr-9hcv-x6pv[ADVISORY]