werkzeug vulnerabilities
CVEs whose affected-version data names the werkzeug package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
10 CVEsRSS
CVE-2026-27199MediumPoCWerkzeug safe_join() allows Windows special device names
Werkzeug safe_join() allows Windows special device names
CVE-2026-21860Medium· 5.3Werkzeug safe_join() allows Windows special device names with compound extensions
Werkzeug safe_join() allows Windows special device names with compound extensions
CVE-2025-66221MediumWerkzeug safe_join() allows Windows special device names
Werkzeug safe_join() allows Windows special device names
CVE-2024-49767High· 7.5Werkzeug possible resource exhaustion when parsing file data in forms
Werkzeug possible resource exhaustion when parsing file data in forms
CVE-2024-49766MediumWerkzeug safe_join not safe on Windows
Werkzeug safe_join not safe on Windows
CVE-2024-34069High· 7.5PoCWerkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
CVE-2023-46136Medium· 5.7PoCWerkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
CVE-2023-25577High· 7.5High resource usage when parsing multipart form data with many fields
High resource usage when parsing multipart form data with many fields
CVE-2023-23934Low· 2.6Incorrect parsing of nameless cookies leads to __Host- cookies bypass
Incorrect parsing of nameless cookies leads to __Host- cookies bypass
CVE-2019-14322High· 7.5PoCPallets Werkzeug vulnerable to Path Traversal
Pallets Werkzeug vulnerable to Path Traversal