CVE-2024-49767 - CVE House
Back to Database
Status published Medium CVE-2024-49767

Werkzeug possible resource exhaustion when parsing file data in forms

Vulnerability Description

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parse `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A specifically crafted form submission request can cause the parser to allocate and block 3 to 8 times the upload size in main memory. There is no upper limit; a single upload at 1 Gbit/s can exhaust 32 GB of RAM in less than 60 seconds. Werkzeug version 3.0.6 fixes this issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-49767

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

werkzeug, Quart
Vulnerable Versions:
>= 2.0.0rc1, < 3.0.6, < 0.20.0

Timeline

Official Publish: October 25th, 2024
Last Modified: May 20th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)