VDB
Sign up
MEDIUM5.3

PYSEC-2026-2044

Werkzeug safe_join() allows Windows special device names with compound extensions

Quick fix

PYSEC-2026-2044 — werkzeug: upgrade to the fixed version with the command below.

pip install --upgrade 'werkzeug>=3.1.5'

Details

Werkzeug's `safe_join` function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are special device names such as `CON`, `AUX`, etc that are implicitly present and readable in every directory. Windows still accepts them with any file extension, such as `CON.txt`, or trailing spaces such as `CON `.

This was previously reported as https://github.com/pallets/werkzeug/security/advisories/GHSA-hgf8-39gv-g3f2, but the fix failed to account for compound extensions such as `CON.txt.html` or trailing spaces. It also missed some additional special names.

`send_from_directory` uses `safe_join` to safely serve files at user-specified paths under a directory. If the application is running on Windows, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/werkzeug
Introduced in: 0Fixed in: 3.1.5
Fixpip install --upgrade 'werkzeug>=3.1.5'

References