CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-102598

CVE-2026-102598: Remote Denial of Service via NTFS Alternate Data Stream Bypass in Werkzeug safe_join

Alon Barad
Alon Barad
Software Engineer

Oct 6, 2026·7 min read·10 visits

Executive Summary (TL;DR)

A validation bypass in Werkzeug's safe_join utility on Windows systems allows attackers to bypass reserved device checks using empty NTFS Alternate Data Stream markers, causing server worker threads to block indefinitely and triggering a Denial of Service.

CVE-2026-102598 is a security bypass and Denial of Service (DoS) vulnerability in the Werkzeug WSGI web application library. In versions prior to 3.1.9, the library's safe_join function fails to sanitize Windows reserved device names containing an empty NTFS Alternate Data Stream (ADS) marker (such as NUL:). This allows remote, unauthenticated attackers to trigger indefinite thread-blocking operations on Windows hosts, resulting in application-wide resource exhaustion.

Vulnerability Overview

Werkzeug is a comprehensive WSGI web application library for Python, widely utilized as the underlying foundation for frameworks such as Flask. In deployment environments running on Microsoft Windows with an NTFS filesystem, the library exposes a path-traversal and file-handling attack surface through its sanitization utilities. Specifically, the utility function safe_join is designed to ensure that untrusted user-supplied file paths are constrained within a target base directory.\n\nA flaw in the validation logic of safe_join allows attackers to bypass checks designed to restrict access to reserved Windows device names. By appending an empty NTFS Alternate Data Stream (ADS) marker, such as NUL:, an attacker can circumvent the blocklist of legacy DOS device names. This bypass allows the path resolution to succeed, leading to dangerous downstream file-system operations on reserved physical hardware names.\n\nThe primary security consequence of this validation bypass is a remote, unauthenticated Denial of Service (DoS). When a downstream component attempts to open and read from the incorrectly resolved device path, the operating system-level file handler blocks execution indefinitely. This resource exhaustion quickly consumes available server worker threads, rendering the application unavailable to legitimate network traffic.

Root Cause Analysis

The root cause of this vulnerability lies in the improper handling of Windows reserved device names, classified under CWE-67. Modern Windows operating systems retain compatibility with legacy MS-DOS device names, including NUL, CON, PRN, AUX, and serial or parallel port identifiers. When applications open these identifiers as file paths, the operating system translates the requests to physical hardware streams or system devices rather than typical storage directories.\n\nTo prevent directory escapes and improper device access, Werkzeug maintains a blocklist of forbidden identifiers inside _windows_device_files and validates path components using safe_join. Prior to version 3.1.9, the validation mechanism checked path segments against this blocklist by partitioning strings around the period (.) character. The logic expected that any file extension or suffix would be isolated, leaving the base name to be evaluated against the restricted device list.\n\nOn NTFS filesystems, files can contain Alternate Data Streams (ADS), defined by a colon (:) separator in the format filename:streamname:streamtype. An empty ADS marker can be appended directly to a device name, resulting in a string such as NUL:. When Werkzeug processed this segment, the partitioning logic looked for a period but found none. Consequently, the string `

Code-Level Analysis and Patch Verification

Evaluating the vulnerable code path demonstrates how the parser missed the Alternate Data Stream marker. In Werkzeug versions prior to 3.1.9, the check evaluated each directory segment in part.split("/") against the legacy device blocklist using a simple partition. The loop evaluated p.partition(".")[0].strip().upper(), which fails when a colon is present instead of a period.\n\npython\n# Vulnerable implementation in Werkzeug < 3.1.9\nos.name == "nt" and any(\n # Partitions only on period, missing the colon separator\n p.partition(".")[0].strip().upper() in _windows_device_files\n for p in part.split("/")\n)\n\n\nThe patch introduced in version 3.1.9 resolves this validation gap by adding a primary partition step targeting the NTFS stream separator. By partitioning the segment on the colon (:) first, the logic effectively strips any Alternate Data Stream identifiers prior to performing the check against the period (.) character. This ensures that the base device name is isolated and properly validated against the blocklist.\n\npython\n# Patched implementation in Werkzeug 3.1.9\nos.name == "nt" and any(\n # First partitions on colon to strip ADS, then on period\n p.partition(":")[0].partition(".")[0].strip().upper()\n in _windows_device_files\n for p in part.split("/")\n)\n\n\nThis corrective code completely closes this bypass vector by ensuring that strings like NUL: are truncated to NUL before the membership test. This fix is robust against variants using multiple colons or combining colons and periods in unexpected sequences. The modification prevents downstream system calls from interacting with the underlying legacy DOS device drivers under any circumstances.

Exploitation Methodology

An attack exploiting CVE-2026-102598 requires specific environmental conditions to trigger successfully. First, the target web application must run on a Windows server utilizing an NTFS filesystem. Second, the application must expose an endpoint that serves static files, downloads, or media resources utilizing Werkzeug's send_from_directory helper or directly invoking safe_join with user-controlled input.\n\nAn unauthenticated attacker begins exploitation by sending a crafted HTTP GET request targeting the file-serving endpoint. The request includes a parameter containing the legacy device name appended with an empty Alternate Data Stream marker, such as ?file=NUL:. Because safe_join fails to flag this string as restricted, it returns the fully resolved path, which is then passed to Python's native open() function.\n\nWhen Windows processes the file-open API call for the resolved path C:\\app\\static\\NUL:, it strips the trailing colon and redirects the operation to the system null device. A read operation on this physical device does not return a typical EOF immediately under these conditions but instead blocks the calling execution thread. Because web application servers rely on a finite pool of worker threads or processes, sequentially submitting these requests quickly exhausts all available threads, resulting in a complete application hang and denial of service.

Impact Assessment

The security impact of CVE-2026-102598 is classified as a localized Denial of Service (DoS) with a CVSS v4.0 score of 6.3. The vulnerability does not allow for remote code execution, privilege escalation, or unauthorized data disclosure. Confidentiality and integrity remain unaffected because the attacker cannot read files outside the directory or write malicious data to the system.\n\nHowever, the availability impact is significant for applications running on affected Windows systems. Each successful exploit payload blocks a single worker thread permanently. In multi-threaded WSGI containers, sending a small number of concurrent requests matching the pool size will completely freeze the application, preventing legitimate users from accessing the system.\n\nBecause Werkzeug is a foundational package for thousands of web applications, the exposure profile is broad, though mitigated by the requirement for a Windows/NTFS environment. Many production environments run on Linux containers, which are inherently immune to this specific MS-DOS device path behavior. For Windows-based enterprise applications, the risk is elevated because the exploit is exceptionally simple to execute and leaves minimal trace in standard web application logs prior to the thread crash.

Remediation and Mitigation

The primary remediation path is upgrading the Werkzeug package to version 3.1.9 or later. This upgrade addresses the vulnerability at the library level, ensuring that all dependent frameworks like Flask are protected without requiring application-level code modifications. Administrators should update their dependencies using package managers and redeploy their application containers.\n\nIn environments where immediate upgrading is not possible, system administrators can apply temporary workarounds. One operational mitigation is to implement an application-level input validation filter. This filter should inspect incoming path parameters and explicitly reject any requests containing colons (:) or matching known Windows reserved device names prior to forwarding the input to Werkzeug's file-handling functions.\n\nAdditionally, deploying Web Application Firewall (WAF) rules or configuring reverse proxies (such as IIS or Nginx) to block URI paths containing colons in query parameters or URL segments can prevent exploit payloads from reaching the application server. For long-term resilience, security teams should consider migrating Python-based web applications to Linux-based container environments, which completely eliminates legacy Windows OS-specific path vulnerabilities.

Official Patches

PalletsFix commit: disallow special name with ads
PalletsPull Request: disallow special name with ads

Technical Appendix

CVSS Score
6.3/ 10
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
EPSS Probability
0.37%
Top 72% most exploited

Affected Systems

Werkzeug WSGI web application library running on Microsoft Windows with NTFS filesystem

Affected Versions Detail

Product
Affected Versions
Fixed Version
Werkzeug
Pallets
< 3.1.93.1.9
AttributeDetail
CWE IDCWE-67
Attack VectorNetwork (AV:N)
CVSS v4.06.3 (Medium)
EPSS Score0.00368 (28.41% Percentile)
ImpactDenial of Service (DoS) via thread exhaustion
Exploit StatusPoC / Public details available
CISA KEV StatusNot listed

MITRE ATT&CK Mapping

T1499.002Endpoint Denial of Service: Service Exhaustion
Impact
CWE-67
Improper Handling of Windows Device Names

The software does not properly sanitize or validate user-supplied input that represents Windows reserved device names, enabling unexpected execution paths or system degradation when these identifiers resolve to physical hardware or system devices instead of typical files.

Known Exploits & Detection

GitHub AdvisoryDetails and analysis regarding the path bypass vector on Windows platforms.

Vulnerability Timeline

Vulnerability fix code committed to pallets/werkzeug repository
2026-09-27
Werkzeug 3.1.9 released and CVE-2026-102598 published
2026-09-29

References & Sources

  • [1]GHSA-g6x2-hccm-hh4m: Security Advisory
  • [2]Werkzeug 3.1.9 Release Notes
  • [3]NVD - CVE-2026-102598
  • [4]CVE.org - CVE-2026-102598

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•11 minutes ago•CVE-2026-102828
9.2

CVE-2026-102828: Remote Code Execution via Configuration and Argument Injection in simple-git

A critical remote code execution vulnerability (CVE-2026-102828) exists in simple-git versions 3.15.0 through 4.0.0. The vulnerability is caused by an incomplete blocklist within the library's default safety enforcement plugin, blockUnsafeOperationsPlugin. Attackers who can control Git configuration arguments or supply command flags to rebase operations can execute arbitrary system commands with the privileges of the parent Node.js process.

Amit Schendel
Amit Schendel
1 views•5 min read
•about 1 hour ago•CVE-2026-102829
9.2

CVE-2026-102829: Security Control Bypass and Command Injection via VISUAL Environment Variable in @simple-git/argv-parser

A critical security control bypass vulnerability exists in @simple-git/argv-parser before version 2.0.1. The package fails to map the VISUAL environment variable to the allowUnsafeEditor rule, allowing attackers who control environment parameters to execute arbitrary commands when Git triggers an interactive editor fallback.

Alon Barad
Alon Barad
4 views•5 min read
•about 2 hours ago•CVE-2026-105752
3.1

CVE-2026-105752: Cross-Tenant Prefix-Cache Information Leak via Cache Salt Omission in vLLM Harmony Path

A vulnerability in vLLM prior to 0.30.0 allows an authenticated multi-tenant attacker to infer execution history and prompt structures of other tenants. The multi-turn Responses API ('Harmony' path) fails to propagate the 'cache_salt' parameter during tool-call continuation steps, storing sensitive prompt prefixes in the global, unsalted cache space.

Alon Barad
Alon Barad
8 views•7 min read
•about 3 hours ago•CVE-2026-105753
6.5

CVE-2026-105753: Reachable Assertion in vLLM Multimodal IPC Cache Leading to Denial of Service

A state desynchronization (cache drift) vulnerability exists in the multimodal Inter-Process Communication (IPC) Least Recently Used (LRU) caches of vLLM. When a multimodal request fails validation after its media hash has been registered on the frontend but before the payload is committed to the backend engine core, the frontend and backend caches drift out of lockstep. A subsequent request reusing the same media triggers an assertion failure in the backend engine core, resulting in a complete denial of service.

Alon Barad
Alon Barad
8 views•5 min read
•about 4 hours ago•CVE-2026-105750
5.9

CVE-2026-105750: Local File Disclosure in Docling via Permissive HTML Rendering Requests Filter

CVE-2026-105750 is a medium-severity local file disclosure vulnerability affecting the Docling and Docling-Slim libraries. When processing HTML documents using the optional Playwright rendering backend, the application fail to validate and restrict request URIs using the file:// scheme. This permits an attacker supplying a crafted HTML file to access, render, and exfiltrate local system files.

Alon Barad
Alon Barad
9 views•7 min read
•about 6 hours ago•CVE-2026-103921
7.4

CVE-2026-103921: TLS Certificate Validation Bypass in @graphql-tools/executor-legacy-ws

A vulnerability in @graphql-tools/executor-legacy-ws prior to version 1.1.35 hardcodes the TLS rejectUnauthorized setting to false for outgoing secure WebSocket (wss://) connections. This defect allows unauthenticated remote attackers to perform Adversary-in-the-Middle (MitM) attacks, capturing or tampering with sensitive connection payloads and subscription data.

Alon Barad
Alon Barad
10 views•6 min read