Werkzeug
Vendor:
First CVE: Oct 23, 2017 · Active for 8 years
14
Total CVEs
More Total CVEs than 91% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Werkzeug over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 23, 2017
8 years ago
Most Recent CVE
Feb 21, 2026
155 days ago
CVE Severity & Scoring
Werkzeug14 CVEs
43%
43%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (7.1%)
Attack Complexity
Low13 (92.9%)
High1 (7.1%)
Unknown0 (0.0%)
User Interaction
None10 (71.4%)
Unknown0 (0.0%)
Required4 (28.6%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None14 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14322HIGH In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames. | Jul 28, 2019 | 7.5 | 73 | NO | YES |
CVE-2024-34069HIGH Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some ci | May 6, 2024 | 7.5 | 34 | NO | YES |
CVE-2022-29361CRITICAL Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests includ | May 25, 2022 | 9.8 | 34 | NO | NO |
CVE-2023-25577HIGH Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited number of parts, including file part | Feb 14, 2023 | 7.5 | 25 | NO | NO |
CVE-2019-14806HIGH Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id. | Aug 9, 2019 | 7.5 | 25 | NO | NO |
CVE-2024-49767HIGH Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 t | Oct 25, 2024 | 7.5 | 24 | NO | NO |
CVE-2023-46136HIGH Werkzeug is a comprehensive WSGI web application library. In versions on the 3.x branch prior to 3.0.1 and on the 2.x branch prior to 2.3.8, if an upload of a file that starts with | Oct 25, 2023 | 7.5 | 24 | NO | NO |
CVE-2026-27199MEDIUM Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segmen | Feb 21, 2026 | 5.3 | 22 | NO | NO |
CVE-2026-21860MEDIUM Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extens | Jan 8, 2026 | 5.3 | 22 | NO | NO |
CVE-2025-66221MEDIUM Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows path segments with Windows device names. On Windows, there ar | Nov 29, 2025 | 5.3 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.1% of CVEs· 97th percentile
Nuclei
1 CVE
7.1% of CVEs· 97th percentile
ExploitDB
1 CVE
7.1% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Werkzeug
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0.0 | 1 | 7.5 | 1.1% | 0 | 0 |