Executive brief
Prefect is an orchestration tool used to manage and monitor data workflows. A security flaw in its health check interface could allow an unauthorized person to bypass authentication checks. This could lead to the exposure of internal system status or other sensitive operational information.
Technical details
An authentication bypass vulnerability exists in Prefect versions prior to 3.6.22 due to an improper implementation of health check exemptions. The vulnerability is located in the `/api/health` component, specifically involving the `endswith()` function used to identify exempt paths. An attacker can manipulate requests to satisfy this string comparison, allowing them to bypass authentication requirements. This is a remote, unauthenticated attack that can result in unauthorized access to health check data. The issue is addressed in version 3.6.22.
Affected products
- PrefectHQ prefect < 3.6.22
Timeline
- 2026-05-04: advisory
- 2026-05-04: disclosed
- 2026-05-22: patched