{"schema_version":1,"title":"werkzeug (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in werkzeug (PyPI): 0 in the last 7 days and 5 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-21860, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/werkzeug","json_url":"https://junglewise.ai/threats/technologies/werkzeug.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/werkzeug","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":15,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":5,"last_365_days":6},"latest":[{"cve":"CVE-2026-21860","cvss":3.1,"epss":0.0048,"slug":"cve-2026-21860-werkzeug-safe-join-allows-windows-special-device-names-with","title":"PYSEC-2026-2044 - Werkzeug safe_join() allows Windows special device names with compound extensions","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:17.057343+00:00","url":"https://junglewise.ai/threats/cve-2026-21860-werkzeug-safe-join-allows-windows-special-device-names-with"},{"cve":"CVE-2025-66221","cvss":4,"epss":0.0051,"slug":"cve-2025-66221-werkzeug-safe-join-allows-windows-special-device-names","title":"PYSEC-2026-2046 - Werkzeug safe_join() allows Windows special device names","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:11.673679+00:00","url":"https://junglewise.ai/threats/cve-2025-66221-werkzeug-safe-join-allows-windows-special-device-names"},{"cve":"CVE-2024-49766","cvss":4,"epss":0.0078,"slug":"cve-2024-49766-werkzeug-safe-join-not-safe-on-windows","title":"PYSEC-2026-2045 - Werkzeug safe_join not safe on Windows","severity":"medium","exploited":false,"published_at":"2026-07-07T14:34:43.390514+00:00","url":"https://junglewise.ai/threats/cve-2024-49766-werkzeug-safe-join-not-safe-on-windows"},{"cve":"CVE-2024-34069","cvss":3.1,"epss":0.034,"slug":"cve-2024-34069-werkzeug-debugger-remote-code-execution-via-attacker-controlled","title":"PYSEC-2026-2043 - Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:41.944642+00:00","url":"https://junglewise.ai/threats/cve-2024-34069-werkzeug-debugger-remote-code-execution-via-attacker-controlled"},{"cve":"CVE-2019-14322","cvss":3.1,"epss":0.558,"slug":"cve-2019-14322-pallets-werkzeug-vulnerable-to-path-traversal","title":"PYSEC-2026-1065 - Pallets Werkzeug vulnerable to Path Traversal","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:28.302032+00:00","url":"https://junglewise.ai/threats/cve-2019-14322-pallets-werkzeug-vulnerable-to-path-traversal"},{"cve":"CVE-2026-27199","cvss":4,"epss":0.0054,"slug":"cve-2026-27199-werkzeug-safe-join-allows-windows-special-device-names","title":"PYSEC-2026-2320 - Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as fi","severity":"medium","exploited":false,"published_at":"2026-02-21T06:17:00.71+00:00","url":"https://junglewise.ai/threats/cve-2026-27199-werkzeug-safe-join-allows-windows-special-device-names"},{"cve":"CVE-2024-49767","cvss":7.5,"epss":0.011,"slug":"cve-2024-49767-pallets-werkzeug-resource-exhaustion-in-multipart-form-parsing","title":"Pallets Werkzeug resource exhaustion in multipart form parsing","severity":"high","exploited":false,"published_at":"2024-10-25T19:44:43+00:00","url":"https://junglewise.ai/threats/cve-2024-49767-pallets-werkzeug-resource-exhaustion-in-multipart-form-parsing"},{"cve":"CVE-2023-46136","cvss":5.7,"epss":0.0107,"slug":"cve-2023-46136-pallets-werkzeug-denial-of-service-in-multipart-parser","title":"Pallets Werkzeug denial of service in multipart parser","severity":"medium","exploited":false,"published_at":"2023-10-25T14:22:59+00:00","url":"https://junglewise.ai/threats/cve-2023-46136-pallets-werkzeug-denial-of-service-in-multipart-parser"},{"cve":"CVE-2023-23934","cvss":3.1,"epss":0.0051,"slug":"cve-2023-23934-incorrect-parsing-of-nameless-cookies-leads-to-host-cookies","title":"PYSEC-2023-57 - Werkzeug is a comprehensive WSGI web application library. Browsers may allow \"nameless\" cookies that look like `=value` instead of `key=valu","severity":"low","exploited":false,"published_at":"2023-02-14T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-23934-incorrect-parsing-of-nameless-cookies-leads-to-host-cookies"},{"cve":"CVE-2023-25577","cvss":3.1,"epss":0.0142,"slug":"cve-2023-25577-high-resource-usage-when-parsing-multipart-form-data-with-many","title":"PYSEC-2023-58 - Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimi","severity":"low","exploited":false,"published_at":"2023-02-14T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-25577-high-resource-usage-when-parsing-multipart-form-data-with-many"},{"cve":"CVE-2022-29361","epss":0.0807,"slug":"cve-2022-29361-pysec-2022-203-disputed-improper-parsing-of-http-requests-in","title":"PYSEC-2022-203 - ** DISPUTED ** Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling usi","severity":"info","exploited":false,"published_at":"2022-05-25T01:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-29361-pysec-2022-203-disputed-improper-parsing-of-http-requests-in"},{"cve":"CVE-2020-28724","cvss":3.1,"epss":0.0168,"slug":"cve-2020-28724-werkzeug-open-redirect-via-double-slash-in-url","title":"PYSEC-2020-157 - Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.","severity":"low","exploited":false,"published_at":"2020-11-18T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-28724-werkzeug-open-redirect-via-double-slash-in-url"},{"slug":"pysec-2019-70-pallets-werkzeug-before-0-15-3-when-used-with-docker-has-d5477a27","title":"PYSEC-2019-70 - Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same mac","severity":"info","exploited":false,"published_at":"2019-08-09T15:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2019-70-pallets-werkzeug-before-0-15-3-when-used-with-docker-has-d5477a27"},{"cve":"CVE-2019-14806","cvss":3.1,"epss":0.0229,"slug":"cve-2019-14806-pallets-werkzeug-insufficient-entropy","title":"PYSEC-2019-140 - Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same mac","severity":"low","exploited":false,"published_at":"2019-08-09T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-14806-pallets-werkzeug-insufficient-entropy"},{"cve":"CVE-2016-10516","cvss":3,"epss":0.0199,"slug":"cve-2016-10516-pallets-werkzeug-cross-site-scripting-vulnerability","title":"PYSEC-2017-43 - Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11","severity":"low","exploited":false,"published_at":"2017-10-23T16:29:00+00:00","url":"https://junglewise.ai/threats/cve-2016-10516-pallets-werkzeug-cross-site-scripting-vulnerability"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"werkzeug (PyPI)","slug":"werkzeug","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://palletsprojects.com/p/werkzeug/","repo_url":"https://github.com/pallets/werkzeug","description":"Werkzeug is a comprehensive WSGI web application library for Python.","url":"https://junglewise.ai/threats/technologies/werkzeug"},"most_severe":[{"cve":"CVE-2024-49767","cvss":7.5,"epss":0.011,"slug":"cve-2024-49767-pallets-werkzeug-resource-exhaustion-in-multipart-form-parsing","title":"Pallets Werkzeug resource exhaustion in multipart form parsing","severity":"high","exploited":false,"published_at":"2024-10-25T19:44:43+00:00","url":"https://junglewise.ai/threats/cve-2024-49767-pallets-werkzeug-resource-exhaustion-in-multipart-form-parsing"},{"cve":"CVE-2023-46136","cvss":5.7,"epss":0.0107,"slug":"cve-2023-46136-pallets-werkzeug-denial-of-service-in-multipart-parser","title":"Pallets Werkzeug denial of service in multipart parser","severity":"medium","exploited":false,"published_at":"2023-10-25T14:22:59+00:00","url":"https://junglewise.ai/threats/cve-2023-46136-pallets-werkzeug-denial-of-service-in-multipart-parser"},{"cve":"CVE-2024-49766","cvss":4,"epss":0.0078,"slug":"cve-2024-49766-werkzeug-safe-join-not-safe-on-windows","title":"PYSEC-2026-2045 - Werkzeug safe_join not safe on Windows","severity":"medium","exploited":false,"published_at":"2026-07-07T14:34:43.390514+00:00","url":"https://junglewise.ai/threats/cve-2024-49766-werkzeug-safe-join-not-safe-on-windows"},{"cve":"CVE-2026-27199","cvss":4,"epss":0.0054,"slug":"cve-2026-27199-werkzeug-safe-join-allows-windows-special-device-names","title":"PYSEC-2026-2320 - Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as fi","severity":"medium","exploited":false,"published_at":"2026-02-21T06:17:00.71+00:00","url":"https://junglewise.ai/threats/cve-2026-27199-werkzeug-safe-join-allows-windows-special-device-names"},{"cve":"CVE-2025-66221","cvss":4,"epss":0.0051,"slug":"cve-2025-66221-werkzeug-safe-join-allows-windows-special-device-names","title":"PYSEC-2026-2046 - Werkzeug safe_join() allows Windows special device names","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:11.673679+00:00","url":"https://junglewise.ai/threats/cve-2025-66221-werkzeug-safe-join-allows-windows-special-device-names"},{"cve":"CVE-2019-14322","cvss":3.1,"epss":0.558,"slug":"cve-2019-14322-pallets-werkzeug-vulnerable-to-path-traversal","title":"PYSEC-2026-1065 - Pallets Werkzeug vulnerable to Path Traversal","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:28.302032+00:00","url":"https://junglewise.ai/threats/cve-2019-14322-pallets-werkzeug-vulnerable-to-path-traversal"},{"cve":"CVE-2024-34069","cvss":3.1,"epss":0.034,"slug":"cve-2024-34069-werkzeug-debugger-remote-code-execution-via-attacker-controlled","title":"PYSEC-2026-2043 - Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:41.944642+00:00","url":"https://junglewise.ai/threats/cve-2024-34069-werkzeug-debugger-remote-code-execution-via-attacker-controlled"},{"cve":"CVE-2019-14806","cvss":3.1,"epss":0.0229,"slug":"cve-2019-14806-pallets-werkzeug-insufficient-entropy","title":"PYSEC-2019-140 - Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same mac","severity":"low","exploited":false,"published_at":"2019-08-09T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-14806-pallets-werkzeug-insufficient-entropy"},{"cve":"CVE-2020-28724","cvss":3.1,"epss":0.0168,"slug":"cve-2020-28724-werkzeug-open-redirect-via-double-slash-in-url","title":"PYSEC-2020-157 - Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.","severity":"low","exploited":false,"published_at":"2020-11-18T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-28724-werkzeug-open-redirect-via-double-slash-in-url"},{"cve":"CVE-2023-25577","cvss":3.1,"epss":0.0142,"slug":"cve-2023-25577-high-resource-usage-when-parsing-multipart-form-data-with-many","title":"PYSEC-2023-58 - Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimi","severity":"low","exploited":false,"published_at":"2023-02-14T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-25577-high-resource-usage-when-parsing-multipart-form-data-with-many"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}