Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3417
  • PyPI/werkzeug
Werkzeug possible resource exhaustion when parsing file data in forms 13 Jul
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2026-2044
  • PyPI/werkzeug
Werkzeug safe_join() allows Windows special device names with compound extensions 07 Jul
  • Fix available
  • Severity - 6.3 (Medium)
PYSEC-2026-2046
  • PyPI/werkzeug
Werkzeug safe_join() allows Windows special device names 07 Jul
  • Fix available
  • Severity - 6.3 (Medium)
PYSEC-2026-2045
  • PyPI/werkzeug
Werkzeug safe_join not safe on Windows 07 Jul
  • Fix available
  • Severity - 6.3 (Medium)
PYSEC-2026-2043
  • PyPI/werkzeug
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain 07 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1065
  • PyPI/werkzeug
Pallets Werkzeug vulnerable to Path Traversal 06 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-2320
  • PyPI/werkzeug
See record for full details 21 Feb
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-29vq-49wr-vm6x
  • PyPI/werkzeug
Werkzeug safe_join() allows Windows special device names 19 Feb
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-87hc-h4r5-73f7
  • PyPI/werkzeug
Werkzeug safe_join() allows Windows special device names with compound extensions 08 Jan
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-hgf8-39gv-g3f2
  • PyPI/werkzeug
Werkzeug safe_join() allows Windows special device names 02 Dec 2025
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-q34m-jh98-gwm2
  • PyPI/quart
  • PyPI/werkzeug
Werkzeug possible resource exhaustion when parsing file data in forms 25 Oct 2024
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-f9vj-2wh5-fj8j
  • PyPI/werkzeug
Werkzeug safe_join not safe on Windows 25 Oct 2024
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-2g68-c3qc-8985
  • PyPI/werkzeug
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain 06 May 2024
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2023-221
  • PyPI/werkzeug
  • github.com/pallets/werkzeug
See record for full details 25 Oct 2023
  • Fix available
  • Severity - 7.5 (High)
GHSA-hrfv-mqp8-q5rw
  • PyPI/werkzeug
Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning 25 Oct 2023
  • Fix available
  • Severity - 5.7 (Medium)
GHSA-px8h-6qxv-m22q
  • PyPI/werkzeug
Incorrect parsing of nameless cookies leads to __Host- cookies bypass 15 Feb 2023
  • Fix available
  • Severity - 2.6 (Low)