CVE-2026-21860
Werkzeug safe_join() allows Windows special device names with compound extensions
Description
Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. Windows still accepts them with any file extension, such as CON.txt, or trailing spaces such as CON. This issue has been patched in version 3.1.5.
No summary for this CVE yet.
CVSS Vector Breakdown
Exploitability
AV:NAttack VectorNetwork
AC:LAttack ComplexityLow
PR:NPrivileges RequiredNone
UI:NUser InteractionNone
Scope
S:UScopeUnchanged
Impact
C:NConfidentialityNone
I:NIntegrityNone
A:LAvailabilityLow
Weaknesses
Affected Products
palletsprojects
oss-project·US
werkzeugLibrary
OSS Libraries / pypipallets
oss-project·US
werkzeugLibrary
OSS Libraries / pypiPyPI
package-ecosystem
Exploitability
Official Patch Available
References
https://github.com/pallets/werkzeug/commit/7ae1d254e04a0c33e241ac1cca4783ce6c875ca3
github.com
https://github.com/pallets/werkzeug/security/advisories/GHSA-87hc-h4r5-73f7
github.com
https://nvd.nist.gov/vuln/detail/CVE-2026-21860
nvd.nist.gov
and 1 more references View all →
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-21860 and every CVE in our database. Create a free account — no credit card required.
Create Free AccountPlain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows
