๐Ÿ” CVE Alert

CVE-2026-102598

UNKNOWN 0.0

Werkzeug safe_join() allows Windows special device names

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first removing an empty NTFS ADS marker. The trigger is that an application runs on Windows with NTFS and serves a user-specified path ending in a special device name such as NUL:. The attack mechanism is that a requested path ends in a Windows special device name with an empty ADS marker. The impact is that the special device opens successfully and the file read hangs indefinitely. This issue is fixed in version 3.1.9.

CWE CWE-67
Vendor pallets
Product werkzeug
Published Sep 29, 2026
Last Updated Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for pallets werkzeug

Be the first to know when new unknown vulnerabilities affecting pallets werkzeug are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

pallets / werkzeug
< 3.1.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/pallets/werkzeug/security/advisories/GHSA-g6x2-hccm-hh4m github.com: https://github.com/pallets/werkzeug/pull/3309 github.com: https://github.com/pallets/werkzeug/commit/8d77320bcdf3a34941ec06dcf16b03c065cd21b6 github.com: https://github.com/pallets/werkzeug/releases/tag/3.1.9