CVE-2026-102598
published 2026-09-29CVE-2026-102598: Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device…
PriorityP340medium6.3CVSS 4.0
AVNACLATPPRNUINVCNVINVALSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.37%
28.5th percentile
Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first removing an empty NTFS ADS marker. The trigger is that an application runs on Windows with NTFS and serves a user-specified path ending in a special device name such as NUL:. The attack mechanism is that a requested path ends in a Windows special device name with an empty ADS marker. The impact is that the special device opens successfully and the file read hangs indefinitely. This issue is fixed in version 3.1.9.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| pallets | werkzeug | < 3.1.9 | 3.1.9 |
| palletsprojects | werkzeug | >= 0 < 3.1.9 | 3.1.9 |
CVSS provenance
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
werkzeug: werkzeug: Denial of Service via safe_join() Windows special device paths
vendor_redhat·2026-09-29·CVSS 6.3
CVE-2026-102598 [MEDIUM] CWE-66 werkzeug: werkzeug: Denial of Service via safe_join() Windows special device paths
werkzeug: werkzeug: Denial of Service via safe_join() Windows special device paths
A flaw was found in werkzeug. A remote attacker can cause a Denial of Service (DoS) when an application runs on Windows systems using the NTFS file system. By supplying a file path containing a reserved Windows device name with an Alternate Data Stream (ADS) marker, an attacker can bypass path sanitization in safe_join(). This causes the server to hang indefinitely while attempting to read the special device, making the service unavailable to users.
Package: python-sentry-sdk (Red Hat Hardened Images) - Not affected
Package: python-urllib3 (Red Hat Hardened Images) - Not affected
VulDB
Pallets Werkzeug up to 3.1.8 Windows Device Name safe_join path traversal (EUVD-2026-88980)
vuldb·2026-10-06·CVSS 6.3
CVE-2026-102598 [MEDIUM] Pallets Werkzeug up to 3.1.8 Windows Device Name safe_join path traversal (EUVD-2026-88980)
A vulnerability was found in Pallets Werkzeug up to 3.1.8. It has been classified as critical. The impacted element is the function safe_join of the component Windows Device Name Handler. This manipulation causes path traversal.
This vulnerability is handled as CVE-2026-102598. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
Werkzeug safe_join() allows Windows special device names
ghsa·2026-10-05
CVE-2026-102598 [MEDIUM] CWE-67 Werkzeug safe_join() allows Windows special device names
Werkzeug safe_join() allows Windows special device names
Werkzeug's `safe_join` function allows Windows device names as filenames when they have an empty ADS marker on NTFS.
This was previously reported as https://github.com/pallets/werkzeug/security/advisories/GHSA-hgf8-39gv-g3f2, but the added filtering failed to account for the fact Windows allows special device names with an empty ADS marker, such as `NUL:`.
`send_from_directory` uses `safe_join` to safely serve files at user-specified paths under a directory. If the application is running on Windows and NTFS, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely.
No detection rules found.
No public exploits indexed.
2026-09-29
Published