VendorsPalletsprojectswerkzeugany version
Vulnerabilities

Palletsprojects The Pallets Projects Werkzeug any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2022-29361
Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body. NOTE: the vendor's position is that this behavior can only occur in unsupported configurations involving development mode and an HTTP server from outside the Werkzeug project
Published 2022-05-24 · Modified
9.8EPSS 0.081
CVE-2023-46136
Werkzeug vulnerable to high resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
Published 2023-10-24 · Modified
8.0EPSS 0.011
CVE-2019-14322
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
Published 2019-07-28 · Modified
7.51 PoCEPSS 0.558
CVE-2024-34069
Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution
Published 2024-05-06 · Analyzed
7.5EPSS 0.034
CVE-2019-14806
Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.
Published 2019-08-09 · Modified
7.5EPSS 0.023
CVE-2023-25577
Werkzeug may allow high resource usage when parsing multipart form data with many fields
Published 2023-02-14 · Modified
7.5EPSS 0.014
CVE-2024-49767
Werkzeug possible resource exhaustion when parsing file data in forms
Published 2024-10-25 · Modified
7.5EPSS 0.011
CVE-2024-49766
Werkzeug safe_join not safe on Windows
Published 2024-10-25 · Analyzed
6.3EPSS 0.008
CVE-2026-27199
Werkzeug safe_join() allows Windows special device names
Published 2026-02-21 · Analyzed
6.3EPSS 0.005
CVE-2025-66221
Werkzeug safe_join() allows Windows special device names
Published 2025-11-29 · Analyzed
6.3EPSS 0.005
CVE-2026-21860
Werkzeug safe_join() allows Windows special device names with compound extensions
Published 2026-01-08 · Analyzed
6.3EPSS 0.005
CVE-2016-10516
Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.
Published 2017-10-23 · Modified
6.1EPSS 0.020
CVE-2020-28724
Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.
Published 2020-11-18 · Modified
6.1EPSS 0.017
CVE-2023-23934
Wrkzeug's incorrect parsing of nameless cookies leads to __Host- cookies bypass
Published 2023-02-14 · Modified
3.5EPSS 0.005