CVE-2024-49767
HighAdvisory
Published 25 Oct 2024In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.011
- 64th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 153
- of 17,781 indexed, latest versions
- Container images
- 152
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Werkzeug possible resource exhaustion when parsing file data in forms
Carried by container images the latest versions of 153 of 17,781 indexed charts deploy, on 152 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| werkzeugpypi | 2.0.0, 2.0.1, 2.0.2, 2.0.3+14 more | 3.0.6 | 152 |
| quartpypi | 0.19.4 | 0.20.0 | 1 |
- OSV records
- GHSA-q34m-jh98-gwm2
- Also known as
- PYSEC-2026-1860, PYSEC-2026-3417
Charts affected
153 by stars
Container images carrying it
152 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | e0d9b93dbf2b | werkzeug | 3.0.6 | 1 |
| registry.gitlab.com/ | 4e7faf6f8d5f | werkzeug | 3.0.6 | 1 |