Back

LOW

Wrkzeug's incorrect parsing of nameless cookies leads to __Host- cookies bypass

Published Feb 14, 2023

Description

Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised application on an adjacent subdomain to exploit this to set a cookie like `=__Host-test=bad` for another subdomain. Werkzeug prior to 2.2.3 will parse the cookie `=__Host-test=bad` as __Host-test=bad`. If a Werkzeug application is running next to a vulnerable or malicious subdomain which sets such a cookie using a vulnerable browser, the Werkzeug application will see the bad cookie value but the valid cookie key. The issue is fixed in Werkzeug 2.2.3.

Affected products

Remediation

No remediation recorded yet.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Feb 14, 2023
Updated Mar 10, 2025
Reserved Jan 19, 2023
CISA Vulnrichment
Updated Mar 10, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 14, 2023
GHSA-PX8H-6QXV-M22Q