Vulnerability PYSEC-2026-3417

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 months ago
July 13, 2026 at 02:36 PM UTC
Werkzeug possible resource exhaustion when parsing file data in forms
2.0.0rc1 - 3.0.5
2.0.0rc1 - 3.0.5

Summary

Werkzeug possible resource exhaustion when parsing file data in forms

Details

Applications using Werkzeug to parse multipart/form-data requests are vulnerable to resource exhaustion. A specially crafted form body can bypass the Request.max_form_memory_size setting.

The Request.max_content_length setting, as well as resource limits provided by deployment software and platforms, are also available to limit the resources used during a request. This vulnerability does not affect those settings. All three types of limits should be considered and set appropriately when deploying an application.

Impacted packages

Timeline

Published
2 months ago
July 13, 2026 at 02:36 PM UTC
Fixed (3.0.6)
1 year ago
October 25, 2024 at 06:52 PM UTC
Last Modified
2 months ago
July 13, 2026 at 04:43 PM UTC