NUL Device Path Vulnerability in Werkzeug Web Application Library
CVE-2026-102598
6.3MEDIUM
What is CVE-2026-102598?
The Werkzeug library utilizes the safe_join function in the send_from_directory endpoint, which can be exploited due to improper handling of special device paths in Windows NTFS. Specifically, if a user-specified path concludes with the special device name NUL:, the function fails to correctly sanitize it, resulting in a vulnerability. This allows an attacker to craft requests that lead to the special device being accessed, causing the file read operation to hang indefinitely. This issue is resolved in version 3.1.9, emphasizing the importance of upgrading to mitigate risks associated with such path traversal vulnerabilities.
Affected Version(s)
werkzeug < 3.1.9
