werkzeug has 10 CVEs on record between 2022 and 2026. The median CVSS is 7.5 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- werkzeug 10
Worst active — by depth score
CVE-2019-14322High· 7.5Pallets Werkzeug vulnerable to Path Traversal64CVE-2024-34069High· 7.5Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain54CVE-2023-46136Medium· 5.7Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning44CVE-2023-25577High· 7.5High resource usage when parsing multipart form data with many fields42CVE-2024-49767High· 7.5Werkzeug possible resource exhaustion when parsing file data in forms41
werkzeug vulnerabilities
CVEs affecting werkzeug, newest first. Open any entry for full detail, references, and exploit status.
10 CVEsRSS
CVE-2026-27199MediumPoCWerkzeug safe_join() allows Windows special device names
Werkzeug safe_join() allows Windows special device names
CVE-2026-21860Medium· 5.3Werkzeug safe_join() allows Windows special device names with compound extensions
Werkzeug safe_join() allows Windows special device names with compound extensions
CVE-2025-66221MediumWerkzeug safe_join() allows Windows special device names
Werkzeug safe_join() allows Windows special device names
CVE-2024-49767High· 7.5Werkzeug possible resource exhaustion when parsing file data in forms
Werkzeug possible resource exhaustion when parsing file data in forms
CVE-2024-49766MediumWerkzeug safe_join not safe on Windows
Werkzeug safe_join not safe on Windows
CVE-2024-34069High· 7.5PoCWerkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
CVE-2023-46136Medium· 5.7PoCWerkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
CVE-2023-25577High· 7.5High resource usage when parsing multipart form data with many fields
High resource usage when parsing multipart form data with many fields
CVE-2023-23934Low· 2.6Incorrect parsing of nameless cookies leads to __Host- cookies bypass
Incorrect parsing of nameless cookies leads to __Host- cookies bypass
CVE-2019-14322High· 7.5PoCPallets Werkzeug vulnerable to Path Traversal
Pallets Werkzeug vulnerable to Path Traversal