CVE-2023-46136 is an algorithmic-complexity denial-of-service vulnerability in Werkzeug multipart/form-data upload parsing. In Werkzeug versions earlier than 3.0.1 on the 3.x branch and earlier than 2.3.8 on the 2.x branch, a multipart file part beginning with a carriage return or line feed and followed by a large amount of data containing neither character causes the parser to append input incrementally to an internal bytearray while repeatedly searching the ever-growing buffer for a boundary. This inefficient boundary detection results in excessive resource consumption.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python proof-of-concept exploit (werkghost.py) for CVE-2025-66221, a denial-of-service vulnerability in Werkzeug versions prior to 3.1.4 when running on Windows. The exploit works by sending multiple concurrent HTTP GET requests to a target URL, appending a Windows device name (such as 'CON') to the path, which causes the Werkzeug server to hang. The script is configurable via command-line arguments for the target URL, directory, payload (device name), number of threads, and request timeout. The README provides usage instructions and notes that the exploit is only effective against Werkzeug servers running on Windows. The repository structure is simple, consisting of a license, a README, and the main exploit script. No hardcoded endpoints are present; the target is specified at runtime. The exploit is a denial-of-service tool and does not provide shell access or code execution.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Python Werkzeug high-resource-consumption vulnerability leading to denial of service.
Unknown
A Python Werkzeug vulnerability that permits high resource consumption and can lead to denial of service.
A high-resource-consumption denial-of-service vulnerability in the Python Werkzeug package, addressed by the Red Hat OpenShift Container Platform 4.13.24 security update.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.