Skip to main content

Vendor archive

palletsprojects CVEs

Beta · best-effort

27 CVEs tagged to vendor palletsprojects1 Critical, 11 High, 13 Medium, 2 Low, 0 Unrated.

CVE-2026-7246

Published Apr 30, 2026

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivile…

CVSS 7.2 · High
evidence mentions
8
Buzz score
40.0
Vendor/product tagsBeta · best-effort

CVE-2026-27205

Published Feb 21, 2026

Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie heade…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-27199

Published Feb 21, 2026

Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segme…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-21860

Published Jan 8, 2026

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file exten…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-66221

Published Nov 29, 2025

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows path segments with Windows device names. On Windows, there a…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27516

Published Mar 5, 2025

Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the…

CVSS 5.4 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2024-56326

Published Dec 23, 2024

Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format allows an attacker that controls the cont…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56201

Published Dec 23, 2024

Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allows an attacker that controls both the content and filename…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49766

Published Oct 25, 2024

Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's safe_join…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22195

Published Jan 11, 2024

Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46136

Published Oct 25, 2023

Werkzeug is a comprehensive WSGI web application library. In versions on the 3.x branch prior to 3.0.1 and on the 2.x branch prior to 2.3.8, if an upload of a file that starts wit…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30861

Published May 2, 2023

Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequen…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25577

Published Feb 14, 2023

Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited number of parts, including file par…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23934

Published Feb 14, 2023

Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a co…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-29361

Published May 25, 2022

Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests inclu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-1010083

Published Jul 17, 2019

The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 27 CVEsPage 1 of 2