📦 Werkzeug

by Palletsprojects

🔍 What is Werkzeug?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-29361

CRITICAL CVSS 9.8 May 25, 2022

CVE-2022-29361 is an HTTP request smuggling vulnerability in Pallets Werkzeug v2.1.0 and below that allows attackers to bypass security controls by sending crafted HTTP requests containing multiple re...

CVE-2024-49767

HIGH CVSS 7.5 Oct 25, 2024

Werkzeug versions before 3.0.6 contain a resource exhaustion vulnerability in the MultiPartParser that handles multipart/form-data requests. Attackers can craft malicious upload requests that cause th...

CVE-2024-34069

HIGH CVSS 7.5 May 6, 2024

This vulnerability in Werkzeug's debugger allows attackers to execute arbitrary code on a developer's machine if they can trick the developer into interacting with a controlled domain/subdomain and en...

CVE-2023-46136

HIGH CVSS 8.0 Oct 25, 2023

CVE-2023-46136 is a denial-of-service vulnerability in Werkzeug's multipart data parser. Attackers can send specially crafted file uploads that cause excessive CPU consumption, blocking worker process...

CVE-2023-25577

HIGH CVSS 7.5 Feb 14, 2023

CVE-2023-25577 is a denial-of-service vulnerability in Werkzeug's multipart form data parser that allows attackers to cause high CPU and memory consumption by sending crafted requests with unlimited p...

CVE-2025-66221

MEDIUM CVSS 5.3 Nov 29, 2025

This vulnerability in Werkzeug's safe_join function allows attackers to cause denial of service by requesting paths ending with Windows device names (like CON, AUX). When exploited on Windows systems,...

CVE-2024-49766

MEDIUM CVSS 5.3 Oct 25, 2024

This vulnerability in Werkzeug's safe_join() function on Windows with Python < 3.11 allows UNC path bypass, potentially enabling directory traversal attacks. Attackers could access files outside inten...