Vulnerability record · CVE-2019-14322 · published 28 July 2019
CVE-2019-14322: Werkzeug SharedDataMiddleware Windows path traversal via drive names
PPalletsprojects · Werkzeug
Pallets Werkzeug before 0.15.5 mishandles drive names such as C: in Windows pathnames within SharedDataMiddleware, allowing path traversal. Because Werkzeug is a widely used WSGI utility library, any application serving static files through this middleware on Windows may expose files outside the intended directory.
Description
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 7.5 with network reachability, no authentication, and a public exploit reference, though no KEV listing and impact limited to confidentiality.
What it is
Pallets Werkzeug before 0.15.5 mishandles drive names such as C: in Windows pathnames within SharedDataMiddleware, allowing path traversal. Because Werkzeug is a widely used WSGI utility library, any application serving static files through this middleware on Windows may expose files outside the intended directory.
Impact
An unauthenticated attacker can read files outside the served directory, resulting in high confidentiality impact with no integrity or availability effect.
Attack surface
Reachable over the network through HTTP requests to an application using SharedDataMiddleware on Windows; the CVSS vector shows no privileges or user interaction required.
Exploitation
A public exploit reference exists (Packet Storm), and EPSS is 0.55803 at the 98.994th percentile, but the CVE is not listed in CISA KEV.
What to do
- Upgrade Werkzeug to 0.15.5 or later, which fixes the drive-name handling in SharedDataMiddleware.
- If immediate upgrade is not possible, avoid exposing SharedDataMiddleware on Windows or restrict it to non-Windows deployments.
- Place static content behind a reverse proxy that normalizes and rejects paths containing drive letters or traversal sequences.
- Run the application with least privilege so file reads are limited to what the service account can access.
Detection
- Monitor HTTP requests for path segments containing drive letters such as C: or traversal sequences like ../.
- Alert on access to files outside the configured static directory by the web service account.
- Review web server and application logs for anomalous static file requests returning 200 for unexpected paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/163398/Pallets-Werkzeug-0.15.4-Path-Traversal.html | ExploitThird Party AdvisoryVDB Entry |
| https://palletsprojects.com/blog/werkzeug-0-15-5-released/ | Release NotesVendor Advisory |
| http://packetstormsecurity.com/files/163398/Pallets-Werkzeug-0.15.4-Path-Traversal.html | ExploitThird Party AdvisoryVDB Entry |
| https://palletsprojects.com/blog/werkzeug-0-15-5-released/ | Release NotesVendor Advisory |
Track CVE-2019-14322 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-14322), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.