CVE-2022-29361
Python vulnerability analysis and mitigation

Overview

CVE-2022-29361 affects Pallets Werkzeug versions 2.1.0 and below. The vulnerability involves improper parsing of HTTP requests that allows attackers to perform HTTP Request Smuggling using crafted HTTP requests with multiple requests included inside the body. The vendor notes that this vulnerability only manifests in unsupported configurations involving development mode and non-Werkzeug HTTP servers (NVD).

Technical details

The vulnerability has been assigned a CVSS v3.1 score of 9.8 (CRITICAL) and a CVSS v2.0 score of 7.5 (HIGH). The vulnerability specifically relates to how Werkzeug handles HTTP request parsing, particularly when dealing with multiple requests embedded within the request body (NVD).

Impact

When exploited, this vulnerability could allow attackers to perform HTTP Request Smuggling attacks. However, the impact is limited to specific configurations where Werkzeug is running in development mode and using a non-Werkzeug HTTP server (NVD).

Mitigation and workarounds

The vendor's position indicates that this vulnerability only occurs in unsupported configurations. Users should ensure they are not running Werkzeug in development mode in production environments and should use supported HTTP server configurations (NVD).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-5882-5rx9-xgxpCRITICAL10
  • PythonPython
  • crawl4ai
NoYesJan 16, 2026
GHSA-vx9w-5cx4-9796HIGH8.6
  • PythonPython
  • crawl4ai
NoYesJan 16, 2026
CVE-2026-23535HIGH8
  • PythonPython
  • wlc
NoYesJan 16, 2026
CVE-2026-23490HIGH7.5
  • PythonPython
  • pyasn1
NoYesJan 16, 2026
CVE-2026-23528MEDIUM5.3
  • PythonPython
  • distributed
NoYesJan 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management