Skip to content

Update dependency Werkzeug to v3.1.9 [SECURITY] - #14631

Open
renovate-bot wants to merge 1 commit into
GoogleCloudPlatform:mainfrom
renovate-bot:renovate/pypi-werkzeug-vulnerability
Open

renovate-bot wants to merge 1 commit into
GoogleCloudPlatform:mainfrom
renovate-bot:renovate/pypi-werkzeug-vulnerability

Conversation

@renovate-bot

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
Werkzeug (changelog) ==3.1.8 → ==3.1.9 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Werkzeug safe_join() allows Windows special device names

CVE-2026-102598 / GHSA-g6x2-hccm-hh4m

More information

Details

Werkzeug's safe_join function allows Windows device names as filenames when they have an empty ADS marker on NTFS.

This was previously reported as GHSA-hgf8-39gv-g3f2, but the added filtering failed to account for the fact Windows allows special device names with an empty ADS marker, such as NUL:.

send_from_directory uses safe_join to safely serve files at user-specified paths under a directory. If the application is running on Windows and NTFS, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely.

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

pallets/werkzeug (Werkzeug)

v3.1.9

Compare Source

Released 2026-09-27

  • safe_join on Windows does not allow special devices names with empty ADS
    markers on NTFS. :ghsa:g6x2-hccm-hh4m
  • ProfilerMiddleware uses profiling.tracing on Python 3.15.
    :issue:3207
  • uri_to_iri and iri_to_uri preserve empty username, password, and
    port 0. :issue:3189
  • Improve performance of parse_options_header. :pr:3231
  • Improve performance of parse_etags. :pr:3231
  • Improve performance of parse_cookie. :pr:3231
  • get_host also checks that the port is in the valid range. :pr:3236
  • The int URL converter returns a 404 instead of 500 error when the value
    is longer than sys.get_int_max_str_digits(). :issue:3237
  • Improve debugger PIN generation from cgroup data inside Podman.
    :issue:3245
  • Authorization parsing basic auth disallows non-base64 characters.
    :pr:3248
  • application/x-www-form-urlencoded form data is no longer limited to
    max_form_memory_size, only max_content_length. :pr:3251
  • LimitedStream.readinto does not resize the buffer when it reads less
    than the remaining size. :pr:3253
  • Rules with 10 or more converters in a single part assign matched values
    correctly. :pr:3254
  • The invalid Range suffix length -0 is no longer accepted. :pr:3255

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@trusted-contributions-gcf trusted-contributions-gcf Bot added kokoro:force-run Add this label to force Kokoro to re-run the tests. owlbot:run Add this label to trigger the Owlbot post processor. labels Oct 7, 2026
@product-auto-label product-auto-label Bot added samples Issues that are directly related to samples. api: appengine Issues related to the App Engine Admin API API. api: bigquery Issues related to the BigQuery API. api: cloudfunctions Issues related to the Cloud Run functions API. api: cloudmedia Issues related to the Media Livestream API. api: cloudprofiler Issues related to the Cloud Profiler API. api: cloudsql api: compute Issues related to the Compute Engine API. api: datastore Issues related to the Datastore API. api: dialogflow Issues related to the Dialogflow API. api: endpoints Issues related to the Cloud Endpoints API. api: iap Issues related to the Identity-Aware Proxy API. api: memorystore api: monitoring Issues related to the Cloud Monitoring API. api: people-and-planet-ai api: recaptchaenterprise Issues related to the reCAPTCHA API. labels Oct 7, 2026
@product-auto-label product-auto-label Bot added the asset: flagship DEE Asset tagging - Flagship. label Oct 7, 2026
@kokoro-team kokoro-team removed the kokoro:force-run Add this label to force Kokoro to re-run the tests. label Oct 7, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the Werkzeug dependency from version 3.1.8 to 3.1.9 across multiple requirements.txt files. The review feedback highlights that Python versions below 3.10 are no longer supported, and recommends removing the outdated environment marker '; python_version >= '3.9'' from several requirements files.

@@ -1,4 +1,4 @@
Flask==3.1.3; python_version >= '3.9'
Werkzeug==3.1.8; python_version >= '3.9'
Werkzeug==3.1.9; python_version >= '3.9'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Python versions below 3.10 are no longer supported. Please remove the environment marker ; python_version >= '3.9' as we should not specify environment markers for Python versions older than 3.10.

Werkzeug==3.1.9
References
  1. Do not specify fallback dependency versions or environment markers for Python versions older than 3.10, as Python versions below 3.10 are no longer supported.

google-auth==2.38.0
google-auth-oauthlib==1.2.1
Werkzeug==3.1.8; python_version >= '3.9'
Werkzeug==3.1.9; python_version >= '3.9'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Python versions below 3.10 are no longer supported. Please remove the environment marker ; python_version >= '3.9' as we should not specify environment markers for Python versions older than 3.10.

Werkzeug==3.1.9
References
  1. Do not specify fallback dependency versions or environment markers for Python versions older than 3.10, as Python versions below 3.10 are no longer supported.

Flask==3.1.3; python_version >= '3.9'
gunicorn==23.0.0
Werkzeug==3.1.8; python_version >= '3.9'
Werkzeug==3.1.9; python_version >= '3.9'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Python versions below 3.10 are no longer supported. Please remove the environment marker ; python_version >= '3.9' as we should not specify environment markers for Python versions older than 3.10.

Werkzeug==3.1.9
References
  1. Do not specify fallback dependency versions or environment markers for Python versions older than 3.10, as Python versions below 3.10 are no longer supported.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api: appengine Issues related to the App Engine Admin API API. api: bigquery Issues related to the BigQuery API. api: cloudfunctions Issues related to the Cloud Run functions API. api: cloudmedia Issues related to the Media Livestream API. api: cloudprofiler Issues related to the Cloud Profiler API. api: cloudsql api: compute Issues related to the Compute Engine API. api: datastore Issues related to the Datastore API. api: dialogflow Issues related to the Dialogflow API. api: endpoints Issues related to the Cloud Endpoints API. api: iap Issues related to the Identity-Aware Proxy API. api: memorystore api: monitoring Issues related to the Cloud Monitoring API. api: people-and-planet-ai api: recaptchaenterprise Issues related to the reCAPTCHA API. asset: flagship DEE Asset tagging - Flagship. owlbot:run Add this label to trigger the Owlbot post processor. samples Issues that are directly related to samples.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants