Vulnerability PYSEC-2026-1860

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
July 07, 2026 at 02:34 PM UTC
Werkzeug possible resource exhaustion when parsing file data in forms
0.1.0 - 0.19.9
0.1.0 - 0.19.9

Summary

Werkzeug possible resource exhaustion when parsing file data in forms

Details

Applications using Werkzeug to parse multipart/form-data requests are vulnerable to resource exhaustion. A specially crafted form body can bypass the Request.max_form_memory_size setting.

The Request.max_content_length setting, as well as resource limits provided by deployment software and platforms, are also available to limit the resources used during a request. This vulnerability does not affect those settings. All three types of limits should be considered and set appropriately when deploying an application.

Impacted packages

Timeline

Published
3 months ago
July 07, 2026 at 02:34 PM UTC
Fixed (0.20.0)
1 year ago
December 23, 2024 at 01:53 PM UTC
Last Modified
2 months ago
July 13, 2026 at 04:43 PM UTC