VDB
Sign up
HIGH7.5

PYSEC-2026-3417

Werkzeug possible resource exhaustion when parsing file data in forms

Quick fix

PYSEC-2026-3417 — werkzeug: upgrade to the fixed version with the command below.

pip install --upgrade 'werkzeug>=3.0.6'

Details

Applications using Werkzeug to parse `multipart/form-data` requests are vulnerable to resource exhaustion. A specially crafted form body can bypass the `Request.max_form_memory_size` setting.

The `Request.max_content_length` setting, as well as resource limits provided by deployment software and platforms, are also available to limit the resources used during a request. This vulnerability does not affect those settings. All three types of limits should be considered and set appropriately when deploying an application.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/werkzeug
Introduced in: 2.0.0rc1Fixed in: 3.0.6
Fixpip install --upgrade 'werkzeug>=3.0.6'

References