CVE-2019-14322High· 7.5▾ MidnightPoC availablePallets Werkzeug vulnerable to Path Traversal
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 11.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
56%
56% → 56%
Exploit-DB · 3 GitHub repos · Nuclei ×1 (last check)
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
werkzeug < 0.15.5Upgrade to a patched release:
werkzeug 0.15.5Connected by shared product, vendor, weakness, or advisory.
CVE-2023-46136Medium· 5.7Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
CVE-2026-27199MediumWerkzeug safe_join() allows Windows special device names
CVE-2024-34069High· 7.5Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
CVE-2023-25577High· 7.5High resource usage when parsing multipart form data with many fields
CVE-2023-23934Low· 2.6Incorrect parsing of nameless cookies leads to __Host- cookies bypass
CVE-2024-49767High· 7.5Werkzeug possible resource exhaustion when parsing file data in forms