---
id: CVE-2024-49767
aliases:
  - GHSA-q34m-jh98-gwm2
  - PYSEC-2026-1860
  - PYSEC-2026-3417
title: Werkzeug possible resource exhaustion when parsing file data in forms
summary: Werkzeug possible resource exhaustion when parsing file data in forms
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: werkzeug
product: werkzeug
ecosystem: pip
affected:
  - 'werkzeug >= 2.0.0rc1, < 3.0.6'
  - quart < 0.20.0
patched:
  - werkzeug 3.0.6
  - quart 0.20.0
published: '2024-10-25'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:19.984825326Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-q34m-jh98-gwm2'
references:
  - url: >-
      https://github.com/pallets/werkzeug/security/advisories/GHSA-q34m-jh98-gwm2
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-49767'
  - url: >-
      https://github.com/pallets/quart/commit/5e78c4169b8eb66b91ead3e62d44721b9e1644ee
  - url: >-
      https://github.com/pallets/quart/commit/abb04a512496206de279225340ed022852fbf51f
  - url: >-
      https://github.com/pallets/werkzeug/commit/50cfeebcb0727e18cc52ffbeb125f4a66551179b
  - url: >-
      https://github.com/pallets/werkzeug/commit/cbb446fdcada7685fce936ded01b76c08dbd6eb5
  - url: 'https://github.com/pallets/werkzeug'
  - url: 'https://github.com/pallets/werkzeug/releases/tag/3.0.6'
  - url: 'https://security.netapp.com/advisory/ntap-20250103-0007'
tags:
  - osv
  - pip
epss: 0.01095
epssPercentile: 0.64066
ingestedAt: '2026-07-08T18:25:52.074Z'
---

## Overview

Applications using Werkzeug to parse `multipart/form-data` requests are vulnerable to resource exhaustion. A specially crafted form body can bypass the `Request.max_form_memory_size` setting.


The `Request.max_content_length` setting, as well as resource limits provided by deployment software and platforms, are also available to limit the resources used during a request. This vulnerability does not affect those settings. All three types of limits should be considered and set appropriately when deploying an application.

## Affected packages

- `werkzeug >= 2.0.0rc1, < 3.0.6`
- `quart < 0.20.0`

## Remediation

Upgrade to a patched release:

- `werkzeug 3.0.6`
- `quart 0.20.0`
