{"id":"CVE-2026-48099","title":"WsgiDAV is a generic and extendable WebDAV server based on WSGI","summary":"WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path lay…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L","cwe":["CWE-22"],"vendor":"wsgidav","product":"wsgidav","affected":["wsgidav <= 4.3.3"],"patched":["wsgidav 4.3.4"],"published":"2026-08-13","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:02:22.660","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-48099","references":[{"url":"https://github.com/mar10/wsgidav/commit/f894ed8656d7bdd7438ab8148c5a02546cb15183","label":"security-advisories@github.com"},{"url":"https://github.com/mar10/wsgidav/security/advisories/GHSA-wxq4-cc2q-338q","label":"security-advisories@github.com"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/wsgidav/PYSEC-2026-3428.yaml","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-wxq4-cc2q-338q"}],"tags":["nvd","ghsa","pip"],"epss":0.00331,"epssPercentile":0.2648,"aliases":["GHSA-wxq4-cc2q-338q"],"ecosystem":"pip","ingestedAt":"2026-07-07T15:41:59.289Z","slug":"CVE-2026-48099","body":"## Overview\n\nWsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-48099)\n\nAffected packages:\n\n- `wsgidav <= 4.3.3`\n\nPatched in:\n\n- `wsgidav 4.3.4`\n\nSource: https://github.com/advisories/GHSA-wxq4-cc2q-338q","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}