NUL Device Path Vulnerability in Werkzeug Web Application Library
CVE-2026-102598

6.3MEDIUM

Key Information:

Vendor

Pallets

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102598?

The Werkzeug library utilizes the safe_join function in the send_from_directory endpoint, which can be exploited due to improper handling of special device paths in Windows NTFS. Specifically, if a user-specified path concludes with the special device name NUL:, the function fails to correctly sanitize it, resulting in a vulnerability. This allows an attacker to craft requests that lead to the special device being accessed, causing the file read operation to hang indefinitely. This issue is resolved in version 3.1.9, emphasizing the importance of upgrading to mitigate risks associated with such path traversal vulnerabilities.

Affected Version(s)

werkzeug < 3.1.9

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.