Junglewise Threat Intelligence

CVE-2025-66221: PYSEC-2026-2046 - Werkzeug safe_join() allows Windows special device names

CVE-2025-66221 · Severity: medium · CVSS 4 · Published 2026-07-07

Technologies: werkzeug (PyPI). Vendors: PyPI.

Executive brief

Werkzeug safe_join() allows Windows special device names

Affected products

  • PyPI werkzeug

Related threats