PT-2026-36754 · Prefecthq · Prefect

Nedlir

·

Published

2026-05-04

·

Updated

2026-05-04

·

CVE-2026-7724

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions PrefectHQ prefect versions prior to 3.6.28.dev2
Description A time-of-check time-of-use (TOCTOU) issue exists in the validate restricted url() function of the Webhook/Notification component. This flaw allows a remote attacker to manipulate the system, although the attack is characterized by high complexity and is difficult to exploit.
Recommendations Update to version 3.6.28.dev2.

Exploit

Fix

Time Of Check To Time Of Use

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2026-7724

Affected Products

Prefect