PT-2026-21351 · Werkzeug · Werkzeug

·

CVE-2026-27199

·

Published

2026-02-19

·

Updated

2026-07-21

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Werkzeug versions 3.1.5 and below
Description The safe join function in Werkzeug, a WSGI web application library, improperly handles Windows device names when used as filenames, particularly when preceded by other path segments. Specifically, the function allows Windows device names as filenames, potentially leading to indefinite hanging when reading files if the application is running on Windows and the requested path ends with a special device name. The send from directory function utilizes safe join to serve files, making it susceptible to this issue.
Recommendations Update to Werkzeug version 3.1.6 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AZ09261
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-MR94452
CLEANSTART-2026-NL78203
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-27199
GHSA-29VQ-49WR-VM6X
PYSEC-2026-2320

Affected Products

Werkzeug