GHSA-q34m-jh98-gwm2MediumCVSS 7.5

Werkzeug possible resource exhaustion when parsing file data in forms

Published
October 25, 2024
Last Modified
May 20, 2026

🔗 CVE IDs covered (1)

📋 Description

Applications using Werkzeug to parse `multipart/form-data` requests are vulnerable to resource exhaustion. A specially crafted form body can bypass the `Request.max_form_memory_size` setting. The `Request.max_content_length` setting, as well as resource limits provided by deployment software and platforms, are also available to limit the resources used during a request. This vulnerability does not affect those settings. All three types of limits should be considered and set appropriately when deploying an application.

🎯 Affected products2

  • pip/Quart:< 0.20.0
  • pip/Werkzeug:>= 2.0.0rc1, <= 3.0.5

🔗 References (9)