{"id":"CVE-2026-48099","aliases":["GHSA-wxq4-cc2q-338q","PYSEC-2026-3428"],"url":"https://o3.security/vulnerability/CVE-2026-48099","summary":"WsgiDAV encoded dot segments can escape filesystem share roots","details":"WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4.","published":"2026-08-13T19:15:01.942Z","modified":"2026-08-16T03:31:25.311294898Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"},"epss":{"score":0.00331,"percentile":0.25707,"asOf":"2026-09-02"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"wsgidav","fixedVersion":"4.3.4"}],"fix":{"url":"https://github.com/mar10/wsgidav/commit/f894ed8656d7bdd7438ab8148c5a02546cb15183","label":"mar10/wsgidav@f894ed8"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48099.json"},{"type":"ADVISORY","url":"https://github.com/mar10/wsgidav/security/advisories/GHSA-wxq4-cc2q-338q"},{"type":"ADVISORY","url":"https://github.com/pypa/advisory-database/tree/main/vulns/wsgidav/PYSEC-2026-3428.yaml"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48099"},{"type":"FIX","url":"https://github.com/mar10/wsgidav/commit/f894ed8656d7bdd7438ab8148c5a02546cb15183"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-16T03:31:25.311294898Z"}}