Werkzeug

Vendor:

First CVE: Oct 23, 2017 · Active for 8 years

14
Total CVEs
More Total CVEs than 91% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Werkzeug over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 23, 2017
8 years ago
Most Recent CVE
Feb 21, 2026
155 days ago

CVE Severity & Scoring

Werkzeug14 CVEs
All CVEs352,713 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (7.1%)
Attack Complexity
Low13 (92.9%)
High1 (7.1%)
Unknown0 (0.0%)
User Interaction
None10 (71.4%)
Unknown0 (0.0%)
Required4 (28.6%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None14 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
Jul 28, 20197.573NOYES
Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some ci
May 6, 20247.534NOYES
Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests includ
May 25, 20229.834NONO
Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited number of parts, including file part
Feb 14, 20237.525NONO
Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.
Aug 9, 20197.525NONO
Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 t
Oct 25, 20247.524NONO
Werkzeug is a comprehensive WSGI web application library. In versions on the 3.x branch prior to 3.0.1 and on the 2.x branch prior to 2.3.8, if an upload of a file that starts with
Oct 25, 20237.524NONO
Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segmen
Feb 21, 20265.322NONO
Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extens
Jan 8, 20265.322NONO
Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows path segments with Windows device names. On Windows, there ar
Nov 29, 20255.322NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.1% of CVEs· 97th percentile
Nuclei
1 CVE
7.1% of CVEs· 97th percentile
ExploitDB
1 CVE
7.1% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Werkzeug

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.0.017.51.1%00