GHSA-g6x2-hccm-hh4m: Pip/Werkzeug vulnerability

Published Oct 5, 2026
·
Updated

Werkzeug's safejoin function allows Windows device names as filenames when they have an empty ADS marker on NTFS.

This was previously reported as https://github.com/pallets/werkzeug/security/advisories/GHSA-hgf8-39gv-g3f2, but the added filtering failed to account for the fact Windows allows special device names with an empty ADS marker, such as NUL:.

sendfromdirectory uses safejoin to safely serve files at user-specified paths under a directory. If the application is running on Windows and NTFS, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely.

Affected Software

1 affected componentFixes available
pip/Werkzeug<3.1.9
3.1.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/Werkzeug to a version that resolves this vulnerability.

    Fixed in 3.1.9

Event History

Oct 5, 2026
Advisory Published
via GitHub·11:48 PM
Data Sourced
via GitHub·11:48 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this issue?

The issue applies when an application uses Werkzeug's send_from_directory on Windows with an NTFS filesystem and serves paths that users can specify. Other operating system and filesystem combinations are not identified as affected by the available information.

2

What does an attacker need to do to trigger the problem?

An attacker needs to request a path ending in a Windows special device name with an empty alternate data stream marker, such as NUL:. When send_from_directory passes that path through safe_join, opening the resulting path succeeds but reading it hangs indefinitely.

3

What is the likely impact of successful exploitation?

The affected file read hangs indefinitely. This can cause denial of service for requests or resources handling those reads.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203