HIGH7.5
PYSEC-2026-1065
Pallets Werkzeug vulnerable to Path Traversal
Quick fix
PYSEC-2026-1065 — werkzeug: upgrade to the fixed version with the command below.
pip install --upgrade 'werkzeug>=0.15.5'Details
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-14322[ADVISORY]
- https://github.com/pallets/werkzeug[WEB]
- https://palletsprojects.com/blog/werkzeug-0-15-5-released[WEB]
- http://packetstormsecurity.com/files/163398/Pallets-Werkzeug-0.15.4-Path-Traversal.html[WEB]
- https://pypi.org/project/werkzeug[PACKAGE]
- https://github.com/advisories/GHSA-j544-7q9p-6xp8[ADVISORY]