PT-2026-2107 · Werkzeug · Werkzeug

·

CVE-2026-21860

·

Published

2026-01-08

·

Updated

2026-07-21

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Werkzeug versions prior to 3.1.5
Description Werkzeug’s safe join function improperly handles path segments containing Windows device names with file extensions or trailing spaces. Windows device names, such as CON and AUX, are implicitly present and readable in every directory and are accepted with file extensions (e.g., CON.txt) or trailing spaces (e.g., CON ). This can lead to unauthorized access or manipulation of system resources.
Recommendations Update Werkzeug to version 3.1.5 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AZ09261
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-MR94452
CLEANSTART-2026-NL78203
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-21860
GHSA-87HC-H4R5-73F7
PYSEC-2026-2044

Affected Products

Werkzeug