Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39297
HistoryFeb 16, 2023 - 8:55 a.m.

Denial Of Service (DoS)

2023-02-1608:55:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
91
werkzeug
denial of service
multipart data
resource usage
application crash

0.001 Low

EPSS

Percentile

50.8%

werkzeug is vulnerable to Denial of Service (DoS) attacks. An attacker is able to cause denial of service conditions by sending a crafted multipart data segment with many file parts to an endpoint which uses request.data, request.form, request.files, or request.get_data, causing high resource usage, possibly resulting in an application crash.