Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)
Published Sep 14, 2026
7.5
HIGHCVSS 3.1
EPSS 0.63%
Description
Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension helper for a caller-supplied name before extension_allowed evaluates an AllExcept denylist. An attacker who controls the name override can use a mixed-case dangerous extension to bypass a lowercase denylist and store the file in the served upload directory. Exploitation requires a denylist configuration, a user-influenced name override, and a deployment that resolves or executes extensions case-insensitively; pure allowlists remain protected and path containment is not bypassed. On an execution-capable upload directory, the stored file can execute with the web server's privileges and affect confidentiality, integrity, and availability. This issue is fixed in version 1.6.0.
Affected products
-
Affected
- < 1.6.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Jugmac00 | Flask-Reuploaded | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-77683 Advisory
- https://github.com/advisories/GHSA-937x-gpqr-72gg Advisory
- https://github.com/jugmac00/flask-reuploaded/commit/5ded76092429c6eb8a4af941b14fbde40a38fff4 x_refsource_MISC
- https://github.com/jugmac00/flask-reuploaded/pull/186 x_refsource_MISC
- https://github.com/jugmac00/flask-reuploaded/security/advisories/GHSA-937x-gpqr-72gg exploitx_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-77683 | Advisory | |
| https://github.com/advisories/GHSA-937x-gpqr-72gg | Advisory | |
| https://github.com/jugmac00/flask-reuploaded/commit/5ded76092429c6eb8a4af941b14fbde40a38fff4 | x_refsource_MISC | |
| https://github.com/jugmac00/flask-reuploaded/pull/186 | x_refsource_MISC | |
| https://github.com/jugmac00/flask-reuploaded/security/advisories/GHSA-937x-gpqr-72gg | exploitx_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub