AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-102598.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 6.3CVSS 4.0 · security-advisories@github.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSAwaiting AnalysisModified Sep 30, 2026

Disclosure summary

Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first removing an empty NTFS ADS marker. The trigger is that an application runs on Windows with NTFS and serves a user-specified path ending in a special device name such as NUL:. The attack mechanism is that a requested path ends in a Windows special device name with an empty ADS marker. The impact is that the special device opens successfully and the file read hangs indefinitely. This issue is fixed in version 3.1.9.

Source-reported weakness categories

CWE-67

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-g6x2-hccm-hh4m

Open original source · Updated Oct 05, 2026

Werkzeug safe_join() allows Windows special device names

Source severity: MEDIUM / 6.3

EcosystemPackageAffected rangeFirst patched
pipWerkzeug< 3.1.93.1.9
NIST National Vulnerability Database · NVD-CVE-2026-102598

Open original source · Updated Sep 30, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

Original records & references

PUBLISHED 2026-09-29T12:17:06-04:00
MODIFIED 2026-09-30T15:38:27-04:00
INGESTED 2026-10-06T11:43:05-04:00