VDB
Sign up
—

PYSEC-2026-2046

Werkzeug safe_join() allows Windows special device names

Quick fix

PYSEC-2026-2046 — werkzeug: upgrade to the fixed version with the command below.

pip install --upgrade 'werkzeug>=3.1.4'

Details

Werkzeug's `safe_join` function allows path segments with Windows device names. On Windows, there are special device names such as `CON`, `AUX`, etc that are implicitly present and readable in every directory. `send_from_directory` uses `safe_join` to safely serve files at user-specified paths under a directory. If the application is running on Windows, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/werkzeug
Introduced in: 0Fixed in: 3.1.4
Fixpip install --upgrade 'werkzeug>=3.1.4'

References