PyPI: werkzeug
CVE-2024-49767
Safety vulnerability ID: SFTY-20241025-51149
Safety legacy ID: pyup.io-73889
Affected versions of Werkzeug are potentially vulnerable to resource exhaustion when parsing file data in forms. Applications using 'werkzeug.formparser.MultiPartParser' to parse 'multipart/form-data' requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A specifically crafted form submission request can cause the parser to allocate and block 3 to 8 times the upload size in main memory. There is no upper limit; a single upload at 1 Gbit/s can exhaust 32 GB of RAM in less than 60 seconds.
Overview
Werkzeug possible resource exhaustion when parsing file data in forms
Advisory
Affected versions of Werkzeug are potentially vulnerable to resource exhaustion when parsing file data in forms. Applications using 'werkzeug.formparser.MultiPartParser' to parse 'multipart/form-data' requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A specifically crafted form submission request can cause the parser to allocate and block 3 to 8 times the upload size in main memory. There is no upper limit; a single upload at 1 Gbit/s can exhaust 32 GB of RAM in less than 60 seconds.
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20241025-51149/CVE-2024-49767
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-49767
- https://github.com/pallets/werkzeug/security/advisories/GHSA-q34m-jh98-gwm2
- https://github.com/pallets/quart/commit/5e78c4169b8eb66b91ead3e62d44721b9e1644ee
- https://github.com/pallets/werkzeug/commit/50cfeebcb0727e18cc52ffbeb125f4a66551179b
- https://nvd.nist.gov/vuln/detail/CVE-2024-49767
- https://github.com/pallets/werkzeug/releases/tag/3.0.6
- https://github.com/pallets/quart/commit/abb04a512496206de279225340ed022852fbf51f
- https://security.netapp.com/advisory/ntap-20250103-0007
- https://github.com/advisories/GHSA-q34m-jh98-gwm2
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
