Skip to main content

Vendor/product archive

palletsprojects / werkzeug CVEs

Beta · best-effort

14 CVEs tagged to palletsprojects / werkzeug1 Critical, 5 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2026-27199

Published Feb 21, 2026

Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segme…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-21860

Published Jan 8, 2026

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file exten…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-66221

Published Nov 29, 2025

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows path segments with Windows device names. On Windows, there a…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49766

Published Oct 25, 2024

Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's safe_join…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46136

Published Oct 25, 2023

Werkzeug is a comprehensive WSGI web application library. In versions on the 3.x branch prior to 3.0.1 and on the 2.x branch prior to 2.3.8, if an upload of a file that starts wit…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25577

Published Feb 14, 2023

Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited number of parts, including file par…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23934

Published Feb 14, 2023

Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a co…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-29361

Published May 25, 2022

Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests inclu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10516

Published Oct 23, 2017

Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other pro…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1