CVE-2026-27199 | Pallets Werkzeug up to 3.1.5 send_from_directory windows device name (GHSA-29vq-49wr-vm6x)
A vulnerability categorized as problematic has been discovered in Pallets Werkzeug up to 3.1.5. Affected by this vulnerability is the function send_from_directory. The manipulation results in improper handling of windows device names.
This vulnerability is reported as CVE-2026-27199. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.