# Flask: what changed from 2 to 3 - Product: Flask (https://whatsnew.fyi/product/flask) - Vendor: Pallets - Range: changelog entries numbered after 2.3.3 up to and including 3.1.3, stable releases only - Entries below: 8 releases (newest first) - Resolved: 2 is 2.3.3 and 3 is 3.1.3, the newest stable release of each major we track - Carrying security changes: 1 · CVEs mentioned: 0 · Mentioning breaking changes: 5 · Removing or deprecating something: 2 - Page: https://whatsnew.fyi/product/flask/compare/2...3 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. ## What changed (24 changes, grouped by kind) ### Added #### 3.1.0 (2024-11-13) - Provide a configuration option to control automatic option responses - Flask.open_resource, open_instance_resource, and Blueprint.open_resource take an encoding parameter to use when opening in text mode, defaulting to utf-8 - Request.max_content_length can be customized per-request instead of only through the MAX_CONTENT_LENGTH config - Add MAX_FORM_MEMORY_SIZE and MAX_FORM_PARTS config options - Add support for the Partitioned cookie attribute (CHIPS) with the SESSION_COOKIE_PARTITIONED config - Support key rotation with the SECRET_KEY_FALLBACKS config, a list of old secret keys that can still be used for unsigning - Request.trusted_hosts is checked during routing and can be set through the TRUSTED_HOSTS config ### Changed #### 3.1.2 (2025-08-19) - Relax type hint for passing bytes IO to send_file #### 3.1.1 (2025-05-13) - flask --help loads the app and plugins first to make sure all commands are shown - Mark sans-io base class as being able to handle views that return AsyncIterable #### 3.1.0 (2024-11-13) - Update minimum dependency versions to Werkzeug >= 3.1, ItsDangerous >= 2.2, Blinker >= 1.9 - -e path takes precedence over default .env and .flaskenv files, and load_dotenv loads default files in addition to a path unless load_defaults=False is passed #### 3.0.3 (2024-04-07) - Initialize the cli attribute in the Flask concrete class instead of in the sansio scaffold ### Fixed #### 3.1.2 (2025-08-19) - stream_with_context does not fail inside async views - When using follow_redirects in the test client, the final state of session is correct #### 3.1.1 (2025-05-13) - Fix signing key selection order when key rotation is enabled via SECRET_KEY_FALLBACKS - Fix type hint for cli_runner.invoke #### 3.1.0 (2024-11-13) - Fix how setting host_matching=True or subdomain_matching=False interacts with SERVER_NAME so that setting SERVER_NAME no longer restricts requests to only that domain #### 3.0.3 (2024-04-07) - Avoid accessing the default hashlib.sha1 at import time to allow developers to change the default in FIPS builds where it may not be available #### 3.0.1 (2024-01-18) - Fix an issue where using other JSON providers, such as flask-orjson, previously caused loaded session data to have an incorrect format in some cases ### Removed #### 3.1.0 (2024-11-13) - Drop support for Python 3.8 #### 3.0.0 (2023-09-30) - Remove previously deprecated code ### Deprecated #### 3.0.0 (2023-09-30) - Add new deprecations ### Security #### 3.1.3 (2026-02-19) - The session is marked as accessed for operations that only access the keys but not the values, such as `in` and `len` _One release carries no categorized changes yet: 3.0.2._ ## Release notes ### 3.1.3 - Date: 2026-02-19 - Version: 3.1.3 - Original notes: https://github.com/pallets/flask/releases/tag/3.1.3 - Permalink: https://whatsnew.fyi/product/flask/releases/3.1.3 - **security** — The session is marked as accessed for operations that only access the keys but not the values, such as `in` and `len` This is the Flask 3.1.3 security fix release, which fixes a security issue but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release. PyPI: https://pypi.org/project/Flask/3.1.3/ Changes: https://flask.palletsprojects.com/page/changes/#version-3-1-3 - The session is marked as accessed for operations that only access the keys but not the values, such as `in` and `len`. [GHSA-68rp-wp8r-4726](https://github.com/pallets/flask/security/advisories/GHSA-68rp-wp8r-4726) ### 3.1.2 - Date: 2025-08-19 - Version: 3.1.2 - Original notes: https://github.com/pallets/flask/releases/tag/3.1.2 - Permalink: https://whatsnew.fyi/product/flask/releases/3.1.2 - **fixed** — stream_with_context does not fail inside async views - **fixed** — When using follow_redirects in the test client, the final state of session is correct - **changed** — Relax type hint for passing bytes IO to send_file This is the Flask 3.1.2 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release. PyPI: https://pypi.org/project/Flask/3.1.2/ Changes: https://flask.palletsprojects.com/page/changes/#version-3-1-2 Milestone: https://github.com/pallets/flask/milestone/38?closed=1 - `stream_with_context` does not fail inside async views. #5774 - When using `follow_redirects` in the test client, the final state of `session` is correct. #5786 - Relax type hint for passing bytes IO to `send_file`. #5776 ### 3.1.1 - Date: 2025-05-13 - Version: 3.1.1 - Original notes: https://github.com/pallets/flask/releases/tag/3.1.1 - Permalink: https://whatsnew.fyi/product/flask/releases/3.1.1 - **fixed** — Fix signing key selection order when key rotation is enabled via SECRET_KEY_FALLBACKS - **fixed** — Fix type hint for cli_runner.invoke - **changed** — flask --help loads the app and plugins first to make sure all commands are shown - **changed** — Mark sans-io base class as being able to handle views that return AsyncIterable This is the Flask 3.1.1 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release. PyPI: https://pypi.org/project/Flask/3.1.1/ Changes: https://flask.palletsprojects.com/en/stable/changes/#version-3-1-1 Milestone https://github.com/pallets/flask/milestone/36?closed=1 - Fix signing key selection order when key rotation is enabled via `SECRET_KEY_FALLBACKS`. GHSA-4grg-w6v8-c28g - Fix type hint for `cli_runner.invoke`. #5645 - `flask --help` loads the app and plugins first to make sure all commands are shown. #5673 - Mark sans-io base class as being able to handle views that return `AsyncIterable`. This is not accurate for Flask, but makes typing easier for Quart. #5659 ### 3.1.0 - Date: 2024-11-13 - Version: 3.1.0 - Original notes: https://github.com/pallets/flask/releases/tag/3.1.0 - Permalink: https://whatsnew.fyi/product/flask/releases/3.1.0 - **removed** — Drop support for Python 3.8 - **changed** — Update minimum dependency versions to Werkzeug >= 3.1, ItsDangerous >= 2.2, Blinker >= 1.9 - **added** — Provide a configuration option to control automatic option responses - **added** — Flask.open_resource, open_instance_resource, and Blueprint.open_resource take an encoding parameter to use when opening in text mode, defaulting to utf-8 - **added** — Request.max_content_length can be customized per-request instead of only through the MAX_CONTENT_LENGTH config - **added** — Add MAX_FORM_MEMORY_SIZE and MAX_FORM_PARTS config options - **added** — Add support for the Partitioned cookie attribute (CHIPS) with the SESSION_COOKIE_PARTITIONED config - **changed** — -e path takes precedence over default .env and .flaskenv files, and load_dotenv loads default files in addition to a path unless load_defaults=False is passed - **added** — Support key rotation with the SECRET_KEY_FALLBACKS config, a list of old secret keys that can still be used for unsigning - **fixed** — Fix how setting host_matching=True or subdomain_matching=False interacts with SERVER_NAME so that setting SERVER_NAME no longer restricts requests to only that domain - **added** — Request.trusted_hosts is checked during routing and can be set through the TRUSTED_HOSTS config This is the Flask 3.1.0 feature release. A feature release may include new features, remove previously deprecated code, add new deprecations, or introduce potentially breaking changes. We encourage everyone to upgrade, and to use a tool such as [pip-tools](https://pypi.org/project/pip-tools/) to pin all dependencies and control upgrades. Test with warnings treated as errors to be able to adapt to deprecation warnings early. PyPI: https://pypi.org/project/Flask/3.1.0/ Changes: https://flask.palletsprojects.com/en/stable/changes/#version-3-1-0 Milestone: https://github.com/pallets/flask/milestone/33?closed=1 - Drop support for Python 3.8. #5623 - Update minimum dependency versions to latest feature releases. Werkzeug >= 3.1, ItsDangerous >= 2.2, Blinker >= 1.9. #5624, #5633 - Provide a configuration option to control automatic option responses. #5496 - `Flask.open_resource`/`open_instance_resource` and `Blueprint.open_resource` take an `encoding` parameter to use when opening in text mode. It defaults to `utf-8`. #5504 - `Request.max_content_length` can be customized per-request instead of only through the `MAX_CONTENT_LENGTH` config. Added `MAX_FORM_MEMORY_SIZE` and `MAX_FORM_PARTS` config. Added documentation about resource limits to the security page. #5625 - Add support for the `Partitioned` cookie attribute (CHIPS), with the `SESSION_COOKIE_PARTITIONED` config. #5472 - `-e path` takes precedence over default `.env` and `.flaskenv` files. `load_dotenv` loads default files in addition to a path unless `load_defaults=False` is passed. #5628 - Support key rotation with the `SECRET_KEY_FALLBACKS` config, a list of old secret keys that can still be used for unsigning. Extensions will need to add support. #5621 - Fix how setting `host_matching=True` or `subdomain_matching=False` interacts with `SERVER_NAME`. Setting `SERVER_NAME` no longer restricts requests to only that domain. #5553 - `Request.trusted_hosts` is checked during routing, and can be set through the `TRUSTED_HOSTS` config. #5636 ### 3.0.3 - Date: 2024-04-07 - Version: 3.0.3 - Original notes: https://github.com/pallets/flask/releases/tag/3.0.3 - Permalink: https://whatsnew.fyi/product/flask/releases/3.0.3 - **fixed** — Avoid accessing the default hashlib.sha1 at import time to allow developers to change the default in FIPS builds where it may not be available - **changed** — Initialize the cli attribute in the Flask concrete class instead of in the sansio scaffold This is a fix release for the 3.0.x feature branch. PyPI: https://pypi.org/project/Flask/3.0.3/ Changes: https://flask.palletsprojects.com/en/3.0.x/changes/#version-3-0-3 Milestone: https://github.com/pallets/flask/milestone/35?closed=1 - The default `hashlib.sha1` may not be available in FIPS builds. Don't access it at import time so the developer has time to change the default. #5448 - Don't initialize the `cli` attribute in the sansio scaffold, but rather in the `Flask` concrete class. #5270 ### 3.0.2 - Date: 2024-02-03 - Version: 3.0.2 - Original notes: https://github.com/pallets/flask/releases/tag/3.0.2 - Permalink: https://whatsnew.fyi/product/flask/releases/3.0.2 This is a fix release for the 3.0.x feature release branch. It fixes bugs but does not otherwise change behavior and should not result in breaking changes. * Changes: https://flask.palletsprojects.com/en/3.0.x/changes/#version-3.0.2 * Milestone: https://github.com/pallets/flask/milestone/34?closed=1 * PyPI: https://pypi.org/project/Flask/3.0.2/ ### 3.0.1 - Date: 2024-01-18 - Version: 3.0.1 - Original notes: https://github.com/pallets/flask/releases/tag/3.0.1 - Permalink: https://whatsnew.fyi/product/flask/releases/3.0.1 - **fixed** — Fix an issue where using other JSON providers, such as flask-orjson, previously caused loaded session data to have an incorrect format in some cases This is a fix release for the 3.0.x feature release branch. Fixes an issue where using other JSON providers, such as `flask-orjson`, previously caused loaded session data to have an incorrect format in some cases. * Changes: https://flask.palletsprojects.com/en/3.0.x/changes/#version-3-0-1 * Milestone: https://github.com/pallets/flask/milestone/32?closed=1 * PyPI: https://pypi.org/project/Flask/3.0.1/ ### 3.0.0 - Date: 2023-09-30 - Version: 3.0.0 - Original notes: https://github.com/pallets/flask/releases/tag/3.0.0 - Permalink: https://whatsnew.fyi/product/flask/releases/3.0.0 - **removed** — Remove previously deprecated code - **deprecated** — Add new deprecations This is a feature release, which includes new features, removes previously deprecated code, and adds new deprecations. The 3.0.x branch is now the supported fix branch, the 2.3.x branch will become a tag marking the end of support for that branch. We encourage everyone to upgrade, and to use a tool such as [pip-tools](https://pypi.org/project/pip-tools/) to pin all dependencies and control upgrades. Test with warnings treated as errors to be able to adapt to deprecation warnings early. * Changes: https://flask.palletsprojects.com/en/3.0.x/changes/#version-3-0-0 * Milestone: https://github.com/pallets/flask/milestone/20?closed=1