VDB
GCVE-110-MAGEIA-2024-351
GCVE-110-MAGEIA-2024-351
Advisory Published
Werkzeug is a Web Server Gateway Interface web application library.
Applications using `werkzeug.formparser.MultiPartParser` corresponding
to a version of Werkzeug prior to 3.0.6 to parsing `multipart/form-data`
requests (e.g. all flask applications) are vulnerable to a relatively
simple but effective resource exhaustion (denial of service) attack. A
specifically crafted form submission request can cause the parser to
allocate and block 3 to 8 times the upload size in main memory. There is
no upper limit; a single upload at 1 Gbit/s can exhaust 32 GB of RAM in
less than 60 seconds. Werkzeug version 3.0.6 fixes this issue.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | python-werkzeug | 0 (affected), 3.0.6-1.mga9 (unaffected) | — |
Aliases
Browse GCVE Records
73,873 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.