{"id":"CVE-2024-49767","aliases":["GHSA-q34m-jh98-gwm2","PYSEC-2026-1860","PYSEC-2026-3417"],"url":"https://o3.security/vulnerability/CVE-2024-49767","summary":"Werkzeug possible resource exhaustion when parsing file data in forms","details":"Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parse `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A specifically crafted form submission request can cause the parser to allocate and block 3 to 8 times the upload size in main memory. There is no upper limit; a single upload at 1 Gbit/s can exhaust 32 GB of RAM in less than 60 seconds. Werkzeug version 3.0.6 fixes this issue.","published":"2024-10-25T19:41:35.029Z","modified":"2026-08-12T03:51:18.840041374Z","cvss":null,"epss":{"score":0.01095,"percentile":0.62534,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"werkzeug","fixedVersion":"3.0.6"},{"ecosystem":"PyPI","name":"quart","fixedVersion":"0.20.0"}],"fix":{"url":"https://github.com/pallets/quart/commit/5e78c4169b8eb66b91ead3e62d44721b9e1644ee","label":"pallets/quart@5e78c41"},"references":[{"type":"WEB","url":"https://github.com/pallets/werkzeug/releases/tag/3.0.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/49xxx/CVE-2024-49767.json"},{"type":"ADVISORY","url":"https://github.com/pallets/werkzeug/security/advisories/GHSA-q34m-jh98-gwm2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-49767"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250103-0007/"},{"type":"FIX","url":"https://github.com/pallets/quart/commit/5e78c4169b8eb66b91ead3e62d44721b9e1644ee"},{"type":"FIX","url":"https://github.com/pallets/quart/commit/abb04a512496206de279225340ed022852fbf51f"},{"type":"FIX","url":"https://github.com/pallets/werkzeug/commit/50cfeebcb0727e18cc52ffbeb125f4a66551179b"},{"type":"WEB","url":"https://github.com/pallets/werkzeug/commit/cbb446fdcada7685fce936ded01b76c08dbd6eb5"},{"type":"PACKAGE","url":"https://github.com/pallets/werkzeug"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20250103-0007"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:18.840041374Z"}}