CVE-2024-49767 is a resource exhaustion vulnerability affecting applications using Werkzeug versions prior to 3.0.6, including Flask applications, when parsing multipart/form-data requests. A specially crafted request can cause the parser to allocate significantly more memory than the upload size, leading to a denial of service. This vulnerability has a CVSS score of 7.5 (High) due to its network-based attack vector and low complexity, allowing an unauthenticated attacker to exhaust system resources. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.19.7CPE matchmatch criteria | cpe:2.3:a:palletsprojects:quart:*:*:*:*:*:python:*:* | ||
< 3.0.6CPE matchmatch criteria | cpe:2.3:a:palletsprojects:werkzeug:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk User Behavior Analytics (UBA) - July 2025
Jul 30, 2025Third-Party Package Updates in Splunk SOAR - July 2025
Jul 7, 2025CVE-2024-49767
Dec 10, 2024Werkzeug possible resource exhaustion when parsing file data in forms
Oct 25, 2024werkzeug: python-werkzeug: Werkzeug possible resource exhaustion when parsing file data in forms
Oct 25, 2024Werkzeug possible resource exhaustion when parsing file data in forms
Oct 8, 2024