Vulnerability PYSEC-2026-2046
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 months ago
July 07, 2026 at 04:03 PM UTC
Werkzeug safe_join() allows Windows special device names
0.1 - 3.1.3
0.1 - 3.1.3
Summary
Werkzeug safe_join() allows Windows special device names
Details
Werkzeug's safe_join function allows path segments with Windows device names. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. send_from_directory uses safe_join to safely serve files at user-specified paths under a directory. If the application is running on Windows, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
8 hours ago
Werkzeug safe_join() allows Windows special device names
0.1 - 3.1.8 GHSA-g6x2-hccm-hh4m
0.1 - 3.1.8 GHSA-g6x2-hccm-hh4m
High Risk
2 months ago
Werkzeug possible resource exhaustion when parsing file data in forms
2.0.0rc1 - 3.0.5 PYSEC-2026-3417
2.0.0rc1 - 3.0.5 PYSEC-2026-3417
Medium Risk
3 months ago
Werkzeug safe_join() allows Windows special device names with compound extensions
0.1 - 3.1.4 PYSEC-2026-2044
0.1 - 3.1.4 PYSEC-2026-2044
Unknown
3 months ago
Werkzeug safe_join not safe on Windows
0.1 - 3.0.5 PYSEC-2026-2045
0.1 - 3.0.5 PYSEC-2026-2045
High Risk
3 months ago
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
0.1 - 3.0.2 PYSEC-2026-2043
0.1 - 3.0.2 PYSEC-2026-2043
Impacted packages
Timeline
Published
3 months ago
July 07, 2026 at 04:03 PM UTC
Fixed (3.1.4)
10 months ago
November 29, 2025 at 02:15 AM UTC
Last Modified
3 months ago
July 07, 2026 at 05:47 PM UTC