Werkzeug
Pallets · 10 CVEs
Werkzeug safe_join() allows Windows special device names
Sep 29, 2026
Werkzeug safe_join() allows Windows special device names
Feb 21, 2026
Werkzeug safe_join() allows Windows special device names with compound extensions
Jan 8, 2026
Werkzeug safe_join() allows Windows special device names
Nov 29, 2025
Werkzeug possible resource exhaustion when parsing file data in forms
Oct 25, 2024
Werkzeug safe_join not safe on Windows
Oct 25, 2024
Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution
May 6, 2024
Werkzeug vulnerable to high resource usage when parsing multipart/form-data containing a large part with CR/LF characte…
Oct 24, 2023
Werkzeug may allow high resource usage when parsing multipart form data with many fields
Feb 14, 2023
Wrkzeug's incorrect parsing of nameless cookies leads to __Host- cookies bypass
Feb 14, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-102598 | Werkzeug safe_join() allows Windows special device names | MEDIUM | 0.37% | Sep 29, 2026 |
| CVE-2026-27199 | Werkzeug safe_join() allows Windows special device names | MEDIUM | 0.54% | Feb 21, 2026 |
| CVE-2026-21860 | Werkzeug safe_join() allows Windows special device names with compound extensions | MEDIUM | 0.47% | Jan 8, 2026 |
| CVE-2025-66221 | Werkzeug safe_join() allows Windows special device names | MEDIUM | 0.51% | Nov 29, 2025 |
| CVE-2024-49767 | Werkzeug possible resource exhaustion when parsing file data in forms | MEDIUM | 1.09% | Oct 25, 2024 |
| CVE-2024-49766 | Werkzeug safe_join not safe on Windows | MEDIUM | 0.78% | Oct 25, 2024 |
| CVE-2024-34069 | Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution | HIGH | 3.40% | May 6, 2024 |
| CVE-2023-46136 | Werkzeug vulnerable to high resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning | HIGH | 1.07% | Oct 24, 2023 |
| CVE-2023-25577 | Werkzeug may allow high resource usage when parsing multipart form data with many fields | HIGH | 1.42% | Feb 14, 2023 |
| CVE-2023-23934 | Wrkzeug's incorrect parsing of nameless cookies leads to __Host- cookies bypass | LOW | 0.51% | Feb 14, 2023 |
Showing 1 to 10 of 10 CVEs