Safety vulnerability ID: 73889
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of Werkzeug are potentially vulnerable to resource exhaustion when parsing file data in forms. Applications using 'werkzeug.formparser.MultiPartParser' to parse 'multipart/form-data' requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A specifically crafted form submission request can cause the parser to allocate and block 3 to 8 times the upload size in main memory. There is no upper limit; a single upload at 1 Gbit/s can exhaust 32 GB of RAM in less than 60 seconds.
Latest version: 3.1.3
The comprehensive WSGI web application library.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application