© 2025-2026 PySpect
First version without a known vulnerability: 3.1.6
Werkzeug safe_join() allows Windows special device names
Fixed in: 3.1.6
Werkzeug safe_join() allows Windows special device names with compound extensions
Fixed in: 3.1.5
Werkzeug safe_join() allows Windows special device names
Fixed in: 3.1.4
Werkzeug possible resource exhaustion when parsing file data in forms
Fixed in: 3.0.6, 0.20.0
Werkzeug safe_join not safe on Windows
Fixed in: 3.0.6
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
Fixed in: 3.0.3
Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
Fixed in: 3.0.1, 2.3.8, f3c803b3ade485a45f12b6d6617595350c0f03e2, f2300208d5e2a5076cbbb4c2aad71096fd040ef9
Incorrect parsing of nameless cookies leads to __Host- cookies bypass
Fixed in: 2.2.3, cf275f42acad1b5950c50ffe8ef58fe62cdce028
High resource usage when parsing multipart form data with many fields
Fixed in: 2.2.3, 517cac5a804e8c4dc4ed038bb20dacd038e7a9f1
** DISPUTED ** Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body. NOTE: the vendor's position is that this behavior can only occur in unsupported configurations involving development mode and an HTTP server from outside the Werkzeug project.
Fixed in: 9a3a981d70d2e9ec3344b5192f86fcaf3210cd85, 2.1.1
Pallets Werkzeug vulnerable to Path Traversal
Fixed in: 0.15.5
Pallets Werkzeug cross-site scripting vulnerability
Fixed in: 0.11.11
Open Redirect in werkzeug
Fixed in: 0.11.6
Pallets Werkzeug Insufficient Entropy
Fixed in: 0.15.3, 00bc43b1672e662e5e3b8cecd79e67fc968fa246