Vulnerability PYSEC-2026-2045
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 months ago
July 07, 2026 at 02:34 PM UTC
Werkzeug safe_join not safe on Windows
0.1 - 3.0.5
0.1 - 3.0.5
Summary
Werkzeug safe_join not safe on Windows
Details
On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's safe_join() relies on this check, and so can produce a path that is not safe, potentially allowing unintended access to data. Applications using Python >= 3.11, or not using Windows, are not vulnerable.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
8 hours ago
Werkzeug safe_join() allows Windows special device names
0.1 - 3.1.8 GHSA-g6x2-hccm-hh4m
0.1 - 3.1.8 GHSA-g6x2-hccm-hh4m
High Risk
2 months ago
Werkzeug possible resource exhaustion when parsing file data in forms
2.0.0rc1 - 3.0.5 PYSEC-2026-3417
2.0.0rc1 - 3.0.5 PYSEC-2026-3417
Medium Risk
3 months ago
Werkzeug safe_join() allows Windows special device names with compound extensions
0.1 - 3.1.4 PYSEC-2026-2044
0.1 - 3.1.4 PYSEC-2026-2044
Unknown
3 months ago
Werkzeug safe_join() allows Windows special device names
0.1 - 3.1.3 PYSEC-2026-2046
0.1 - 3.1.3 PYSEC-2026-2046
High Risk
3 months ago
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
0.1 - 3.0.2 PYSEC-2026-2043
0.1 - 3.0.2 PYSEC-2026-2043
Impacted packages
Timeline
Published
3 months ago
July 07, 2026 at 02:34 PM UTC
Fixed (3.0.6)
1 year ago
October 25, 2024 at 06:52 PM UTC
Last Modified
3 months ago
July 07, 2026 at 05:47 PM UTC