Skip to content

Update dependency werkzeug to v3.1.9 [SECURITY] - #486

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pypi-werkzeug-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pypi-werkzeug-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
werkzeug (changelog) 3.1.8 → 3.1.9 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Werkzeug safe_join() allows Windows special device names

CVE-2026-102598 / GHSA-g6x2-hccm-hh4m

More information

Details

Werkzeug's safe_join function allows Windows device names as filenames when they have an empty ADS marker on NTFS.

This was previously reported as GHSA-hgf8-39gv-g3f2, but the added filtering failed to account for the fact Windows allows special device names with an empty ADS marker, such as NUL:.

send_from_directory uses safe_join to safely serve files at user-specified paths under a directory. If the application is running on Windows and NTFS, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely.

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

pallets/werkzeug (werkzeug)

v3.1.9

Compare Source

Released 2026-09-27

  • safe_join on Windows does not allow special devices names with empty ADS
    markers on NTFS. :ghsa:g6x2-hccm-hh4m
  • ProfilerMiddleware uses profiling.tracing on Python 3.15.
    :issue:3207
  • uri_to_iri and iri_to_uri preserve empty username, password, and
    port 0. :issue:3189
  • Improve performance of parse_options_header. :pr:3231
  • Improve performance of parse_etags. :pr:3231
  • Improve performance of parse_cookie. :pr:3231
  • get_host also checks that the port is in the valid range. :pr:3236
  • The int URL converter returns a 404 instead of 500 error when the value
    is longer than sys.get_int_max_str_digits(). :issue:3237
  • Improve debugger PIN generation from cgroup data inside Podman.
    :issue:3245
  • Authorization parsing basic auth disallows non-base64 characters.
    :pr:3248
  • application/x-www-form-urlencoded form data is no longer limited to
    max_form_memory_size, only max_content_length. :pr:3251
  • LimitedStream.readinto does not resize the buffer when it reads less
    than the remaining size. :pr:3253
  • Rules with 10 or more converters in a single part assign matched values
    correctly. :pr:3254
  • The invalid Range suffix length -0 is no longer accepted. :pr:3255

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Coverage

Converter - python code coverage
FileStmtsMissBranchBrPartCoverMissing
constants.py9000100% 
conversion_mixin.py2912194%25->26, 26
converter.py91512194%31->32, 32–33, 116, 127–128
database.py3734288%24->25, 25–26, 46->48, 66
logging_config.py46410388%33->34, 34–35, 41->42, 42, 48->49, 49
mongodb_monitoring.py17040100% 
tracing.py4596180%59–60, 66->70, 70, 76–78, 80–82
utils.py176574696%61–62, 77->78, 78, 85->84, 90->exit, 128->129, 129, 140->141, 141, 206->209
cisu_transcoders
   base_cisu_converter.py3330091%7, 25, 31
   constants.py5000100% 
   identical_cisu_converter.py9000100% 
   utils.py15060100% 
cisu_transcoders/create_case
   create_case_cisu_constants.py39000100% 
   create_case_cisu_converter.py215244298%159->162, 162, 277->278, 278
cisu_transcoders/reference
   reference_cisu_constants.py2000100% 
   reference_converter.py17000100% 
cisu_transcoders/resources_info
   resources_info_cisu_constants.py12000100% 
   resources_info_cisu_converter.py171332397%174->175, 175, 200->201, 201, 388->389, 389
   resources_info_cisu_helper.py49318293%57->58, 58, 62->63, 63, 66
cisu_transcoders/resources_status
   resources_status_constants.py4000100% 
   resources_status_converter.py4114098%33
cisu_version_converters
   base_cisu_version_converter.py2824191%9, 55->61, 61
   identical_cisu_version_converter.py9000100% 
cisu_version_converters/create_case
   create_case_version_converter.py40040100% 
cisu_version_converters/reference
   reference_version_converter.py14000100% 
cisu_version_converters/resources_info_cisu
   resources_info_cisu_version_converter.py510080%9
conversion_strategy
   cisu_transcoding_strategy.py49222294%51->72, 72, 96->97, 97
   cisu_version_conversion_strategy.py2328287%36->37, 37, 38->39, 39
   conversion_strategy.py1516190%30->36, 36
   health_version_conversion_strategy.py460240100% 
health_version_converters
   base_message_converter.py831214286%13, 72–74, 83->86, 86, 95->98, 98, 102, 106, 110, 114, 118, 124
   error_converter.py510080%9
   identical_message_converter.py15000100% 
   utils.py26512282%32->34, 34–37, 41->43, 43
health_version_converters/create_case_health
   constants.py4000100% 
   create_case_health_converter.py1780800100% 
   create_case_health_update_converter.py5000100% 
health_version_converters/create_case_health/v1_v2
   constants.py17000100% 
   utils.py46022297%36->34, 59->exit
health_version_converters/create_case_health/v2_v3
   constants.py29000100% 
health_version_converters/geo_positions_update
   geo_positions_update_constants.py4000100% 
   geo_positions_update_converter.py49312489%30->33, 33, 43->44, 44, 69->73, 80->81, 81
health_version_converters/geo_resources_details
   geo_resources_details_constants.py4000100% 
   geo_resources_details_converter.py27040100% 
health_version_converters/reference
   reference_constants.py2000100% 
   reference_converter.py13000100% 
health_version_converters/resources_engagement
   resources_engagement_constants.py3000100% 
   resources_engagement_converter.py2202196%33->40
health_version_converters/resources_info
   resources_info_constants.py20000100% 
   resources_info_converter.py87036398%119->156, 171->exit, 210->233
health_version_converters/resources_request
   resources_request_constants.py2000100% 
   resources_request_converter.py21000100% 
health_version_converters/resources_response
   resources_response_constants.py4000100% 
   resources_response_converter.py16020100% 
health_version_converters/resources_status
   resources_status_constants.py10000100% 
   resources_status_converter.py39000100% 
models
   persisted_message.py13000100% 
nomenclatures
   utils.py260140100% 
nomenclatures/from_v1_9_to_v2_3
   health_motive.py1000100% 
   location_kind.py1000100% 
   risk_threat.py1000100% 
   whats_happen.py1000100% 
nomenclatures/from_v2_3_to_v1_9
   health_motive.py1000100% 
   location_kind.py1000100% 
   risk_threat.py1000100% 
   whats_happen.py1000100% 
repositories
   message_repository.py701212283%90–91, 98, 118–120, 122–123, 125, 171–173
TOTAL2139804944395% 

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Overall Project 48.23% 🍏

There is no coverage information present for the Files changed

@renovate renovate Bot changed the title chore(deps): update dependency werkzeug to v3.1.9 [security] Update dependency werkzeug to v3.1.9 [SECURITY] Oct 7, 2026
@renovate
renovate Bot force-pushed the renovate/pypi-werkzeug-vulnerability branch from b11ea9b to a85c22e Compare October 7, 2026 09:34
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Overall Project 48.23% 🍏

There is no coverage information present for the Files changed

@renovate
renovate Bot force-pushed the renovate/pypi-werkzeug-vulnerability branch from a85c22e to dac5734 Compare October 8, 2026 13:23
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Overall Project 48.23% 🍏

There is no coverage information present for the Files changed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants