CVE-2026-102598
Published 29 September 2026 · tracked since 30 September 2026
Description
Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first removing an empty NTFS ADS marker. The trigger is that an application runs
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-72897 HIGH 7.5
- CVE-2026-54873
- CVE-2026-54875 LOW 3.7
- CVE-2026-19743 HIGH 7.8
- CVE-2026-35189
- CVE-2026-35191
- CVE-2026-42772
- CVE-2026-102600 HIGH 7.5
- CVE-2026-102601 LOW 3.5
- CVE-2026-102630 MEDIUM 4.7