28 Total advisories
28 Vulnerabilities
0 Malware

Dependency scanning

Check whether werkzeug is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
PyPI

CVE-2026-27199

Werkzeug safe_join() allows Windows special device names

MEDIUM 5.3
PyPI

CVE-2026-21860

Werkzeug safe_join() allows Windows special device names with compound extensions

UNKNOWN
PyPI

CVE-2025-66221

Werkzeug safe_join() allows Windows special device names

HIGH 7.5
PyPI

CVE-2024-49767

Werkzeug possible resource exhaustion when parsing file data in forms

UNKNOWN
PyPI

CVE-2024-49766

Werkzeug safe_join not safe on Windows

HIGH 7.5
PyPI

CVE-2024-34069

Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain

LOW 2.6
PyPI

CVE-2023-23934

Incorrect parsing of nameless cookies leads to __Host- cookies bypass

MEDIUM 5.7
PyPI

CVE-2023-46136

Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning

HIGH 7.5
PyPI

CVE-2023-25577

High resource usage when parsing multipart form data with many fields

HIGH 7.5
PyPI

CVE-2024-49767

Werkzeug possible resource exhaustion when parsing file data in forms

MEDIUM 5.3
PyPI

CVE-2026-27199

CVE-2026-27199

HIGH 7.5
PyPI

CVE-2024-34069

Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain

MEDIUM 5.3
PyPI

CVE-2026-21860

Werkzeug safe_join() allows Windows special device names with compound extensions

UNKNOWN
PyPI

CVE-2025-66221

Werkzeug safe_join() allows Windows special device names

UNKNOWN
PyPI

CVE-2024-49766

Werkzeug safe_join not safe on Windows

HIGH 7.5
PyPI

CVE-2019-14322

Pallets Werkzeug vulnerable to Path Traversal

HIGH 7.5
PyPI

CVE-2019-14322

Pallets Werkzeug vulnerable to Path Traversal

MEDIUM 6.1
PyPI

CVE-2016-10516

Pallets Werkzeug cross-site scripting vulnerability

MEDIUM 6.1
PyPI

CVE-2020-28724

Open Redirect in werkzeug

HIGH 7.5
PyPI

CVE-2019-14806

Pallets Werkzeug Insufficient Entropy

HIGH 7.5
PyPI

CVE-2023-46136

CVE-2023-46136

UNKNOWN
PyPI

CVE-2023-25577

CVE-2023-25577

UNKNOWN
PyPI

CVE-2023-23934

CVE-2023-23934

UNKNOWN
PyPI

CVE-2022-29361

CVE-2022-29361

UNKNOWN
PyPI

CVE-2020-28724

CVE-2020-28724

UNKNOWN
PyPI

CVE-2019-14806

CVE-2019-14806

UNKNOWN
PyPI

CVE-2016-10516

CVE-2016-10516

UNKNOWN
PyPI

PYSEC-2019-70

PYSEC-2019-70

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes