Palletsprojects
Palletsprojects Werkzeug: vulnerabilities and CVEs
Palletsprojects Werkzeug has 16 published vulnerabilities, 5 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs16
Last 12 months5
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-102598 | Medium (6.3) | 0.37% | — | Sep 29, 2026 | Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without… |
| CVE-2026-7041 | Low (2.9) | 0.42% | — | Apr 26, 2026 | A vulnerability was detected in 666ghj MiroFish up to 0.1.2. The impacted element is an unknown function of the file /console of the component Werkzeug Debugger PIN Handler. Performing a manipulation of the argument… |
| CVE-2026-27199 | Medium (6.3) | 0.54% | — | Feb 21, 2026 | Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segments. This was previously reported as… |
| CVE-2026-21860 | Medium (6.3) | 0.48% | — | Jan 8, 2026 | Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows,… |
| CVE-2025-66221 | Medium (6.3) | 0.51% | — | Nov 29, 2025 | Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows path segments with Windows device names. On Windows, there are special device names such as CON,… |
| CVE-2024-49767 | Medium (6.9) | 1.1% | — | Oct 25, 2024 | Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parse `multipart/form-data` requests… |
| CVE-2024-49766 | Medium (6.3) | 0.78% | — | Oct 25, 2024 | Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's safe_join() relies on this check, and so can… |
| CVE-2024-34069 | High (7.5) | 3.4% | — | May 6, 2024 | Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some circumstances. This requires the attacker… |
| CVE-2023-46136 | High (7.5) | 1.1% | — | Oct 25, 2023 | Werkzeug is a comprehensive WSGI web application library. In versions on the 3.x branch prior to 3.0.1 and on the 2.x branch prior to 2.3.8, if an upload of a file that starts with CR or LF and then is followed by… |
| CVE-2023-25577 | High (7.5) | 1.4% | — | Feb 14, 2023 | Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited number of parts, including file parts. Parts can be a small amount of… |
| CVE-2023-23934 | Low (3.5) | 0.51% | — | Feb 14, 2023 | Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised application on an adjacent… |
| CVE-2022-29361 | Critical (9.8) | 8.1% | — | May 25, 2022 | Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body. NOTE: the vendor's… |
| CVE-2020-28724 | Medium (6.1) | 1.7% | — | Nov 18, 2020 | Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL. |
| CVE-2019-14806 | High (7.5) | 2.3% | — | Aug 9, 2019 | Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id. |
| CVE-2019-14322 | High (7.5) | 56% | — | Jul 28, 2019 | In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames. |
| CVE-2016-10516 | Medium (6.1) | 2.0% | — | Oct 23, 2017 | Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.