๐Ÿ” CVE Alert

CVE-2026-48099

HIGH 7.1

WsgiDAV encoded dot segments can escape filesystem share roots

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4.

CWE CWE-22
Vendor mar10
Product wsgidav
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for mar10 wsgidav

Be the first to know when new high vulnerabilities affecting mar10 wsgidav are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

mar10 / wsgidav
< 4.3.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mar10/wsgidav/security/advisories/GHSA-wxq4-cc2q-338q github.com: https://github.com/mar10/wsgidav/commit/f894ed8656d7bdd7438ab8148c5a02546cb15183 github.com: https://github.com/pypa/advisory-database/tree/main/vulns/wsgidav/PYSEC-2026-3428.yaml