Description
Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer. This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. This vulnerability has been patched in version 3.0.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0280 | Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer. This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. This vulnerability has been patched in version 3.0.1. |
Github GHSA |
GHSA-hrfv-mqp8-q5rw | Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning |
References
History
Fri, 27 Jun 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat ceph Storage
|
|
| CPEs | cpe:/a:redhat:ceph_storage:8.1::el9 | |
| Vendors & Products |
Redhat ceph Storage
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-13T17:14:17.737Z
Reserved: 2023-10-16T17:51:35.574Z
Link: CVE-2023-46136
No data.
Status : Modified
Published: 2023-10-25T18:17:36.753
Modified: 2024-11-21T08:27:57.400
Link: CVE-2023-46136
OpenCVE Enrichment
No data.
EUVD
Github GHSA