Technology · PyPI
werkzeug (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 15 vulnerabilities in werkzeug (PyPI): 0 in the last 7 days and 5 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-21860, was published on 7 July 2026.
- Last 7 days
- 0
- Last 90 days
- 5
- Critical, all time
- 0
- Exploited in the wild
- 0
About werkzeug (PyPI)
Werkzeug is a comprehensive WSGI web application library for Python.
Latest werkzeug (PyPI) vulnerabilities
- CVE-2026-21860: PYSEC-2026-2044 - Werkzeug safe_join() allows Windows special device names with compound extensionslowCVSS 3.1EPSS 0.5%
- CVE-2025-66221: PYSEC-2026-2046 - Werkzeug safe_join() allows Windows special device namesmediumCVSS 4EPSS 0.5%
- CVE-2024-49766: PYSEC-2026-2045 - Werkzeug safe_join not safe on WindowsmediumCVSS 4EPSS 0.8%
- CVE-2024-34069: PYSEC-2026-2043 - Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domainlowCVSS 3.1EPSS 3.4%
- CVE-2019-14322: PYSEC-2026-1065 - Pallets Werkzeug vulnerable to Path TraversallowCVSS 3.1EPSS 55.8%
- CVE-2026-27199: PYSEC-2026-2320 - Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join…mediumCVSS 4EPSS 0.5%
- CVE-2024-49767: Pallets Werkzeug resource exhaustion in multipart form parsinghighCVSS 7.5EPSS 1.1%
- CVE-2023-46136: Pallets Werkzeug denial of service in multipart parsermediumCVSS 5.7EPSS 1.1%
- CVE-2023-23934: PYSEC-2023-57 - Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look…lowCVSS 3.1EPSS 0.5%
- CVE-2023-25577: PYSEC-2023-58 - Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart…lowCVSS 3.1EPSS 1.4%
- CVE-2022-29361: PYSEC-2022-203 - ** DISPUTED ** Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to…infoEPSS 8.1%
- CVE-2020-28724: PYSEC-2020-157 - Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.lowCVSS 3.1EPSS 1.7%
- PYSEC-2019-70 - Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers…info
- CVE-2019-14806: PYSEC-2019-140 - Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because…lowCVSS 3.1EPSS 2.3%
- CVE-2016-10516: PYSEC-2017-43 - Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger…lowCVSS 3EPSS 2.0%
Most severe werkzeug (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-49767: Pallets Werkzeug resource exhaustion in multipart form parsinghighCVSS 7.5EPSS 1.1%
- CVE-2023-46136: Pallets Werkzeug denial of service in multipart parsermediumCVSS 5.7EPSS 1.1%
- CVE-2024-49766: PYSEC-2026-2045 - Werkzeug safe_join not safe on WindowsmediumCVSS 4EPSS 0.8%
- CVE-2026-27199: PYSEC-2026-2320 - Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join…mediumCVSS 4EPSS 0.5%
- CVE-2025-66221: PYSEC-2026-2046 - Werkzeug safe_join() allows Windows special device namesmediumCVSS 4EPSS 0.5%
- CVE-2019-14322: PYSEC-2026-1065 - Pallets Werkzeug vulnerable to Path TraversallowCVSS 3.1EPSS 55.8%
- CVE-2024-34069: PYSEC-2026-2043 - Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domainlowCVSS 3.1EPSS 3.4%
- CVE-2019-14806: PYSEC-2019-140 - Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because…lowCVSS 3.1EPSS 2.3%
- CVE-2020-28724: PYSEC-2020-157 - Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.lowCVSS 3.1EPSS 1.7%
- CVE-2023-25577: PYSEC-2023-58 - Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart…lowCVSS 3.1EPSS 1.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 5 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/werkzeug.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "werkzeug (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/werkzeug, 26 September 2026.