Skip to main content

CWE archive

CWE-67 CVEs

Programmatic archive

5 CVEs tagged with CWE-670 Critical, 0 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2026-27199

Published Feb 21, 2026

Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segme…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-21860

Published Jan 8, 2026

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file exten…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-66221

Published Nov 29, 2025

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows path segments with Windows device names. On Windows, there a…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51745

Published Nov 5, 2024

Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks access to special device filenames such as "COM1", "COM2", "L…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-35197

Published May 23, 2024

gitoxide is a pure Rust implementation of Git. On Windows, fetching refs that clash with legacy device names reads from the devices, and checking out paths that clash with such na…

CVSS 5.4 · Medium
Showing 1-5 of 5 CVEsPage 1 of 1