VulnSea

werkzeug has 10 CVEs on record between 2022 and 2026. The median CVSS is 7.5 (high). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
0 prev 0

Products

  • werkzeug 10
10
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

werkzeug vulnerabilities

CVEs affecting werkzeug, newest first. Open any entry for full detail, references, and exploit status.

10 CVEsRSS

CVE-2026-27199MediumPoC
7mo ago

Werkzeug safe_join() allows Windows special device names

Werkzeug safe_join() allows Windows special device names

Twilightwerkzeug · werkzeugEPSS 0.58%via OSV
CVE-2026-21860Medium· 5.3
8mo ago

Werkzeug safe_join() allows Windows special device names with compound extensions

Werkzeug safe_join() allows Windows special device names with compound extensions

Sunlitwerkzeug · werkzeugEPSS 0.48%via OSV
CVE-2025-66221Medium
9mo ago

Werkzeug safe_join() allows Windows special device names

Werkzeug safe_join() allows Windows special device names

Sunlitwerkzeug · werkzeugEPSS 0.51%via OSV
CVE-2024-49767High· 7.5
1y ago

Werkzeug possible resource exhaustion when parsing file data in forms

Werkzeug possible resource exhaustion when parsing file data in forms

Twilightwerkzeug · werkzeugEPSS 1.1%via OSV
CVE-2024-49766Medium
1y ago

Werkzeug safe_join not safe on Windows

Werkzeug safe_join not safe on Windows

Sunlitwerkzeug · werkzeugEPSS 0.78%via OSV
CVE-2024-34069High· 7.5PoC
2y ago

Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain

Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain

Midnightwerkzeug · werkzeugEPSS 3.4%via OSV
CVE-2023-46136Medium· 5.7PoC
2y ago

Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning

Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning

Twilightwerkzeug · werkzeugEPSS 1.1%via OSV
CVE-2023-25577High· 7.5
3y ago

High resource usage when parsing multipart form data with many fields

High resource usage when parsing multipart form data with many fields

Twilightwerkzeug · werkzeugEPSS 1.4%via OSV
CVE-2023-23934Low· 2.6
3y ago

Incorrect parsing of nameless cookies leads to __Host- cookies bypass

Incorrect parsing of nameless cookies leads to __Host- cookies bypass

Sunlitwerkzeug · werkzeugEPSS 0.51%via OSV
CVE-2019-14322High· 7.5PoC
4y ago

Pallets Werkzeug vulnerable to Path Traversal

Pallets Werkzeug vulnerable to Path Traversal

Midnightwerkzeug · werkzeugEPSS 56%via OSV
werkzeug vulnerabilities (CVEs) · VulnSea