CVE-2026-102598
CVE-2026-102598 is a medium-severity vulnerability with a CVSS 4.0 base score of 6.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-67.
Key facts
- Severity: Medium (CVSS 4.0 base score 6.3)
- EPSS exploit prediction: 0% (29th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-67
- Published:
- Last modified:
Description
Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first removing an empty NTFS ADS marker. The trigger is that an application runs on Windows with NTFS and serves a user-specified path ending in a special device name such as NUL:. The attack mechanism is that a requested path ends in a Windows special device name with an empty ADS marker. The impact is that the special device opens successfully and the file read hangs indefinitely. This issue is fixed in version 3.1.9.
Frequently asked questions
- What is CVE-2026-102598?
- Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first removing an empty NTFS ADS marker. The trigger is that an application runs on Windows with NTFS and serves a user-specified path ending in a special device name such as NUL:. The attack mechanism is that a requested path ends in a Windows special device name with an empty ADS marker. The impact is that the special device opens successfully and the file read hangs indefinitely. This issue is fixed in version 3.1.9.
- How severe is CVE-2026-102598?
- CVE-2026-102598 has a CVSS 4.0 base score of 6.3, rated medium severity.
- Is CVE-2026-102598 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (29th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-102598?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-102598 published?
- CVE-2026-102598 was published on 2026-09-29 and last updated on 2026-09-30.
References
- https://github.com/pallets/werkzeug/commit/8d77320bcdf3a34941ec06dcf16b03c065cd21b6
- https://github.com/pallets/werkzeug/pull/3309
- https://github.com/pallets/werkzeug/releases/tag/3.1.9
- https://github.com/pallets/werkzeug/security/advisories/GHSA-g6x2-hccm-hh4m
Other CWE-67 vulnerabilities
- CVE-2024-51745 — Critical (CVSS 10.0): Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks…
- CVE-2026-17545 — Medium (CVSS 6.9): On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to…
- CVE-2024-35197 — Medium (CVSS 5.4): gitoxide is a pure Rust implementation of Git. On Windows, fetching refs that clash with legacy device names reads from…
- CVE-2026-27199 — Medium (CVSS 5.3): Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows…
- CVE-2026-21860 — Medium (CVSS 5.3): Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows…
- CVE-2025-66221 — Medium (CVSS 5.3): Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows…