Repository navigation
Update dependency Werkzeug to v3.1.9 [SECURITY] - #14631
renovate-bot wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Code Review
This pull request updates the Werkzeug dependency from version 3.1.8 to 3.1.9 across multiple requirements.txt files. The review feedback highlights that Python versions below 3.10 are no longer supported, and recommends removing the outdated environment marker '; python_version >= '3.9'' from several requirements files.
| @@ -1,4 +1,4 @@ | |||
| Flask==3.1.3; python_version >= '3.9' | |||
| Werkzeug==3.1.8; python_version >= '3.9' | |||
| Werkzeug==3.1.9; python_version >= '3.9' | |||
There was a problem hiding this comment.
Python versions below 3.10 are no longer supported. Please remove the environment marker ; python_version >= '3.9' as we should not specify environment markers for Python versions older than 3.10.
Werkzeug==3.1.9
References
- Do not specify fallback dependency versions or environment markers for Python versions older than 3.10, as Python versions below 3.10 are no longer supported.
| google-auth==2.38.0 | ||
| google-auth-oauthlib==1.2.1 | ||
| Werkzeug==3.1.8; python_version >= '3.9' | ||
| Werkzeug==3.1.9; python_version >= '3.9' |
There was a problem hiding this comment.
Python versions below 3.10 are no longer supported. Please remove the environment marker ; python_version >= '3.9' as we should not specify environment markers for Python versions older than 3.10.
Werkzeug==3.1.9
References
- Do not specify fallback dependency versions or environment markers for Python versions older than 3.10, as Python versions below 3.10 are no longer supported.
| Flask==3.1.3; python_version >= '3.9' | ||
| gunicorn==23.0.0 | ||
| Werkzeug==3.1.8; python_version >= '3.9' | ||
| Werkzeug==3.1.9; python_version >= '3.9' |
There was a problem hiding this comment.
Python versions below 3.10 are no longer supported. Please remove the environment marker ; python_version >= '3.9' as we should not specify environment markers for Python versions older than 3.10.
Werkzeug==3.1.9
References
- Do not specify fallback dependency versions or environment markers for Python versions older than 3.10, as Python versions below 3.10 are no longer supported.
This PR contains the following updates:
==3.1.8→==3.1.9Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Werkzeug safe_join() allows Windows special device names
CVE-2026-102598 / GHSA-g6x2-hccm-hh4m
More information
Details
Werkzeug's
safe_joinfunction allows Windows device names as filenames when they have an empty ADS marker on NTFS.This was previously reported as GHSA-hgf8-39gv-g3f2, but the added filtering failed to account for the fact Windows allows special device names with an empty ADS marker, such as
NUL:.send_from_directoryusessafe_jointo safely serve files at user-specified paths under a directory. If the application is running on Windows and NTFS, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely.Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
pallets/werkzeug (Werkzeug)
v3.1.9Compare Source
Released 2026-09-27
safe_joinon Windows does not allow special devices names with empty ADSmarkers on NTFS. :ghsa:
g6x2-hccm-hh4mProfilerMiddlewareusesprofiling.tracingon Python 3.15.:issue:
3207uri_to_iriandiri_to_uripreserve empty username, password, andport 0. :issue:
3189parse_options_header. :pr:3231parse_etags. :pr:3231parse_cookie. :pr:3231get_hostalso checks that the port is in the valid range. :pr:3236intURL converter returns a 404 instead of 500 error when the valueis longer than
sys.get_int_max_str_digits(). :issue:3237:issue:
3245Authorizationparsingbasicauth disallows non-base64 characters.:pr:
3248application/x-www-form-urlencodedform data is no longer limited tomax_form_memory_size, onlymax_content_length. :pr:3251LimitedStream.readintodoes not resize the buffer when it reads lessthan the remaining size. :pr:
3253correctly. :pr:
3254Rangesuffix length-0is no longer accepted. :pr:3255Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.