
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21860 is a vulnerability in Werkzeug's safe_join() function that improperly handles Windows reserved device names (e.g., CON, AUX, PRN, NUL, COM1–COM9, LPT1–LPT9) when they appear with file extensions or trailing spaces (e.g., CON.txt, CON.txt.html, CON ). This is a bypass of a prior incomplete fix (GHSA-hgf8-39gv-g3f2) that failed to account for compound extensions and additional special names. All Werkzeug versions prior to 3.1.5 are affected; the issue is Windows-specific and does not affect Linux/POSIX deployments. It was disclosed on January 8, 2026, with a CVSS v3.1 score of 5.3 (Medium) and a CVSS v4.0 score of 6.3 (Medium) (Github Advisory, Werkzeug Advisory).
The root cause is CWE-67 (Improper Handling of Windows Device Names): Werkzeug's safe_join() function in src/werkzeug/security.py checked only the base name via os.path.splitext(filename)[0], which failed to strip compound extensions (e.g., CON.txt.html) or trailing spaces before comparing against the blocklist of reserved device names. The fix in version 3.1.5 changes the check to use filename.partition(".")[0].strip().upper(), correctly isolating the device name stem before any extension or whitespace. The send_from_directory() function relies on safe_join() to safely serve user-specified file paths; on Windows, if a path resolves to a device name, the OS opens it successfully but reading hangs indefinitely, causing a denial of service. The expanded blocklist in the patch also adds CONIN$, CONOUT$, and superscript-suffixed COM/LPT variants (Werkzeug Advisory, Patch Commit).
Exploitation causes an availability impact on Windows-hosted Werkzeug applications: when a request path resolves to a Windows device name, the server thread or process hangs indefinitely waiting for a read from the device, effectively causing a denial of service for that request handler. There is no confidentiality or integrity impact assessed by the CNA. Applications using send_from_directory() or any code path invoking safe_join() with user-controlled input on Windows are directly affected; downstream products including IBM Netezza Appliance, IBM QRadar Suite Software, IBM Rapid Infrastructure Automation, IBM Cloud Pak for Security, IBM watsonx Data Intelligence, and Dell Automation Platform have also been identified as affected (Github Advisory, Feedly).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.023% (7th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Detection plugins are available via Nessus (plugin 282536) and Qualys (ID 6626575) (Feedly).
send_from_directory() or a similar function using safe_join().CON.txt, CON.txt.html, AUX.log, or CON (with trailing space).GET /files/CON.txt HTTP/1.1).CON.txt, CON.txt.html, AUX.log, NUL.dat, COM1.cfg, LPT1.txt, CON with trailing space); repeated requests from the same source IP targeting such paths.Upgrade Werkzeug to version 3.1.5 or later, which corrects the safe_join() logic to properly strip compound extensions and trailing spaces before checking against the Windows device name blocklist (Werkzeug Advisory, Patch Commit). If immediate patching is not possible, implement additional server-side input validation to reject filenames matching Windows device name patterns before they reach safe_join(). Restricting access to file-serving endpoints or deploying a WAF rule to block requests with device-name filenames can serve as a temporary mitigation. IBM and Dell have issued separate advisories for their affected products and should be consulted for product-specific patch guidance (IBM Netezza Advisory, Feedly).
The vulnerability was reported by security researchers yueyueL and MushroomWasp and patched by Werkzeug maintainer davidism on January 8, 2026 (Werkzeug Advisory). Multiple downstream vendors including IBM and Dell have issued security bulletins acknowledging the impact on their products. No significant broader community controversy or media coverage has been identified beyond standard vulnerability disclosure channels.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."