CVE-2026-21860: medium-severity vulnerability in pallets werkzeug
Werkzeug safe_join() allows Windows special device names with compound extensions
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.3epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. Windows still accepts them with any file extension, such as CON.txt, or trailing spaces such as CON. This issue has been patched in version 3.1.5.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected products
pallets · werkzeugRelated CVEs — pallets werkzeug
In the same product, most dangerous first.
CVE-2024-34069HIGHWerkzeug's improper usage of a pathname and improper CSRF protection results in the remote command executionEPSS 3.4%CVE-2023-25577HIGHWerkzeug may allow high resource usage when parsing multipart form data with many fieldsEPSS 1.4%CVE-2024-49767MEDIUMWerkzeug possible resource exhaustion when parsing file data in formsEPSS 1.1%CVE-2023-46136HIGHWerkzeug vulnerable to high resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginningEPSS 1.1%CVE-2024-49766MEDIUMWerkzeug safe_join not safe on WindowsEPSS 0.8%CVE-2026-27199MEDIUMWerkzeug safe_join() allows Windows special device namesEPSS 0.5%