Dependency scanning
Check whether werkzeug is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-27199
Werkzeug safe_join() allows Windows special device names
CVE-2026-21860
Werkzeug safe_join() allows Windows special device names with compound extensions
CVE-2025-66221
Werkzeug safe_join() allows Windows special device names
CVE-2024-49767
Werkzeug possible resource exhaustion when parsing file data in forms
CVE-2024-49766
Werkzeug safe_join not safe on Windows
CVE-2024-34069
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
CVE-2023-23934
Incorrect parsing of nameless cookies leads to __Host- cookies bypass
CVE-2023-46136
Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
CVE-2023-25577
High resource usage when parsing multipart form data with many fields
CVE-2024-49767
Werkzeug possible resource exhaustion when parsing file data in forms
CVE-2026-27199
CVE-2026-27199
CVE-2024-34069
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
CVE-2026-21860
Werkzeug safe_join() allows Windows special device names with compound extensions
CVE-2025-66221
Werkzeug safe_join() allows Windows special device names
CVE-2024-49766
Werkzeug safe_join not safe on Windows
CVE-2019-14322
Pallets Werkzeug vulnerable to Path Traversal
CVE-2019-14322
Pallets Werkzeug vulnerable to Path Traversal
CVE-2016-10516
Pallets Werkzeug cross-site scripting vulnerability
CVE-2020-28724
Open Redirect in werkzeug
CVE-2019-14806
Pallets Werkzeug Insufficient Entropy
CVE-2023-46136
CVE-2023-46136
CVE-2023-25577
CVE-2023-25577
CVE-2023-23934
CVE-2023-23934
CVE-2022-29361
CVE-2022-29361
CVE-2020-28724
CVE-2020-28724
CVE-2019-14806
CVE-2019-14806
CVE-2016-10516
CVE-2016-10516
PYSEC-2019-70
PYSEC-2019-70
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes