CVE-2026-102598
Received Received - Intake

Path Traversal in Werkzeug via NUL Device

Vulnerability report for CVE-2026-102598, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitHub, Inc.

Description

Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first removing an empty NTFS ADS marker. The trigger is that an application runs on Windows with NTFS and serves a user-specified path ending in a special device name such as NUL:. The attack mechanism is that a requested path ends in a Windows special device name with an empty ADS marker. The impact is that the special device opens successfully and the file read hangs indefinitely. This issue is fixed in version 3.1.9.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
werkzeug werkzeug 3.1.9

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-67 The product constructs pathnames from user input, but it does not handle or incorrectly handles a pathname containing a Windows device name such as AUX or CON. This typically leads to denial of service or an information exposure when the application attempts to process the pathname as a regular file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Werkzeug library, a WSGI web application tool. It involves the safe_join function in versions before 3.1.9, which fails to properly handle Windows NTFS ADS markers when checking device names. This allows a path ending in a special device name like NUL: to bypass checks, causing the application to hang indefinitely when reading the file.

Detection Guidance

The vulnerability affects Windows systems running Werkzeug versions before 3.1.9 where NTFS is used. Check Werkzeug version with pip show Werkzeug. Monitor for file read hangs when accessing paths ending in Windows special device names like NUL:. No specific commands are provided in the context.

Impact Analysis

If you run a Windows system with NTFS and use a vulnerable Werkzeug version, an attacker could send a request with a path ending in a special device name. This would cause the server to hang, leading to denial of service for legitimate users.

Compliance Impact

This vulnerability could lead to service disruptions, potentially violating availability requirements in GDPR or HIPAA. Downtime may result in non-compliance if systems fail to meet uptime or responsiveness standards.

Mitigation Strategies

Upgrade Werkzeug to version 3.1.9 or later. If upgrading is not possible, restrict access to paths ending in Windows special device names on NTFS systems. Review application logs for unusual file read attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102598. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart