Palletsprojects maintains a focused but widely embedded collection of Python web frameworks and utilities—including Flask, Werkzeug, Jinja, Click, and Quart—that are fundamental dependencies across countless web applications and development toolchains. Despite the modestly sized product footprint, the vendor's prominence in the Python ecosystem means that vulnerabilities propagate broadly through downstream applications, and the disclosures have acquired public exploit code at a moderate tendency. The recurring weakness classes center on web-application layers: cross-site scripting and input-neutralization flaws in templating and request handling, resource-consumption issues, and Windows path-handling edge cases that reflect the parser and I/O demands of a widely ported framework suite. Defenders should treat Palletsprojects releases as supply-chain events and audit downstream consumers; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Palletsprojects over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14322HIGH In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames. | Jul 28, 2019 | 7.5 | 73 | NO | YES |
CVE-2024-34069HIGH Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some ci | May 6, 2024 | 7.5 | 34 | NO | YES |
CVE-2022-29361CRITICAL Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests includ | May 25, 2022 | 9.8 | 34 | NO | NO |
CVE-2026-7246HIGH Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileg | Apr 30, 2026 | 7.2 | 32 | NO | NO |
CVE-2016-10745HIGH In Pallets Jinja before 2.8.1, str.format allows a sandbox escape. | Apr 8, 2019 | 8.6 | 29 | NO | NO |
CVE-2019-10906HIGH In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape. | Apr 7, 2019 | 8.6 | 29 | NO | NO |
CVE-2025-27516HIGH Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the c | Mar 5, 2025 | 8.8 | 27 | NO | NO |
CVE-2024-56201HIGH Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allows an attacker that controls both the content and filename o | Dec 23, 2024 | 8.8 | 27 | NO | NO |
CVE-2018-1000656HIGH The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading | Aug 20, 2018 | 7.5 | 26 | NO | NO |
CVE-2024-56326HIGH Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format allows an attacker that controls the conte | Dec 23, 2024 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Palletsprojects.
Media articles that mention a CVE ID that affects a product developed by Palletsprojects — matched by CVE ID, not by vendor name.