OSPulse

Is werkzeug healthy, maintained, and safe?

50/ 100
werkzeugv3.1.8
Medium riskconfidence: Highview on pypi.org

Maintained, but watch it — Werkzeug has real signals (drift, thin maintenance, or advisories) worth tracking.

vital-signs traceirregular · weakening

The verdict

On the OSPulse health scale, Werkzeug lands at 50/100 — medium risk, computed deterministically from live PyPI release history, and the OSV vulnerability database. Maintained, but watch it — Werkzeug has real signals (drift, thin maintenance, or advisories) worth tracking.

The last release was 2 April 2026 (157 days ago); still within a normal window, but the cadence has quietened. Across 105 releases the cadence has been steady, which is a good sign of an ongoing maintenance rhythm. PyPI doesn't expose a reliable maintainer count, so bus-factor isn't scored here — treat maintenance depth as unknown rather than assumed.

OSV lists 27 known advisories for Werkzeug, including 4 high. Review whether your version is in the affected range and whether a fixed release is available before depending on it. Each advisory is listed with its OSV/GHSA identifier below.

Werkzeug is usable but carries real signals — pin versions, watch for new advisories, and keep a fallback in mind. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own requirements.txt through the free health check, or have OSPulse monitor your whole dependency tree continuously.

Evidence trail — deterministic, auditable

Last release recency
157 days ago · quiet
-5
Release cadence
steady · typical gap ~30d
Maintainer bus factor
not available from PyPI — not penalised
Known vulnerabilities (OSV)
27 advisories · 4 high
-45
Package age
18.8 years · 105 releases

Known vulnerabilities (27)

  • GHSA-29vq-49wr-vm6xMODERATECVE-2026-27199PYSEC-2026-2320

    Werkzeug safe_join() allows Windows special device names

  • GHSA-2g68-c3qc-8985HIGHCVE-2024-34069PYSEC-2026-2043

    Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain

  • GHSA-3p3h-qghp-hvh2MODERATECVE-2020-28724PYSEC-2020-157

    Open Redirect in werkzeug

  • GHSA-87hc-h4r5-73f7MODERATECVE-2026-21860PYSEC-2026-2044

    Werkzeug safe_join() allows Windows special device names with compound extensions

  • GHSA-f9vj-2wh5-fj8jMODERATECVE-2024-49766PYSEC-2026-2045

    Werkzeug safe_join not safe on Windows

  • GHSA-gq9m-qvpx-68hcHIGHCVE-2019-14806PYSEC-2019-140

    Pallets Werkzeug Insufficient Entropy

  • GHSA-h2fp-xgx6-xh6fMODERATECVE-2016-10516PYSEC-2017-43

    Pallets Werkzeug cross-site scripting vulnerability

  • GHSA-hgf8-39gv-g3f2MODERATECVE-2025-66221PYSEC-2026-2046

    Werkzeug safe_join() allows Windows special device names

  • GHSA-hrfv-mqp8-q5rwMODERATECVE-2023-46136PYSEC-2023-221

    Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning

  • GHSA-j544-7q9p-6xp8HIGHCVE-2019-14322PYSEC-2026-1065

    Pallets Werkzeug vulnerable to Path Traversal

  • GHSA-px8h-6qxv-m22qLOWCVE-2023-23934PYSEC-2023-57

    Incorrect parsing of nameless cookies leads to __Host- cookies bypass

  • GHSA-q34m-jh98-gwm2MODERATECVE-2024-49767PYSEC-2026-1860PYSEC-2026-3417

    Werkzeug possible resource exhaustion when parsing file data in forms

  • GHSA-xg9f-g7g7-2323HIGHCVE-2023-25577PYSEC-2023-58

    High resource usage when parsing multipart form data with many fields

  • PYSEC-2017-43UNKNOWNCVE-2016-10516GHSA-h2fp-xgx6-xh6f

    Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote

  • PYSEC-2019-140UNKNOWNCVE-2019-14806GHSA-gq9m-qvpx-68hc

    Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.

  • PYSEC-2020-157UNKNOWNCVE-2020-28724GHSA-3p3h-qghp-hvh2

    Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.

  • PYSEC-2022-203UNKNOWNCVE-2022-29361

    ** DISPUTED ** Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included in

  • PYSEC-2023-221LOWCVE-2023-46136GHSA-hrfv-mqp8-q5rw

    Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are ap

  • PYSEC-2023-57UNKNOWNCVE-2023-23934GHSA-px8h-6qxv-m22q

    Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised application

  • PYSEC-2023-58UNKNOWNCVE-2023-25577GHSA-xg9f-g7g7-2323

    Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited number of parts, including file parts. Parts can be a sm

  • PYSEC-2026-1065LOWCVE-2019-14322GHSA-j544-7q9p-6xp8

    Pallets Werkzeug vulnerable to Path Traversal

  • PYSEC-2026-2043LOWCVE-2024-34069GHSA-2g68-c3qc-8985

    Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain

  • PYSEC-2026-2044LOWCVE-2026-21860GHSA-87hc-h4r5-73f7

    Werkzeug safe_join() allows Windows special device names with compound extensions

  • PYSEC-2026-2045MEDIUMCVE-2024-49766GHSA-f9vj-2wh5-fj8j

    Werkzeug safe_join not safe on Windows

  • PYSEC-2026-2046MEDIUMCVE-2025-66221GHSA-hgf8-39gv-g3f2

    Werkzeug safe_join() allows Windows special device names

  • PYSEC-2026-2320LOWCVE-2026-27199GHSA-29vq-49wr-vm6x

    Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segments. This was previou

  • PYSEC-2026-3417LOWCVE-2024-49767GHSA-q34m-jh98-gwm2PYSEC-2026-1860

    Werkzeug possible resource exhaustion when parsing file data in forms

Key facts

Latest version
v3.1.8
Last release
2 April 2026 (157 days ago)
Total releases
105
First release
9 December 2007
Package age
18.8 years
Maintainers
not exposed by PyPI
Known advisories
27
Confidence
High

Frequently asked

Is Werkzeug still maintained?

Partly — the most recent release was 2 April 2026 (157 days ago), so maintenance has slowed but not fully stopped.

Does Werkzeug have known security vulnerabilities?

Yes — OSV lists 27 advisories for Werkzeug. See the advisory list on this page for the OSV/GHSA identifiers.

Is Werkzeug safe to use?

Maintained, but watch it — Werkzeug has real signals (drift, thin maintenance, or advisories) worth tracking. OSPulse rates it 50/100 (medium risk) based on release recency, cadence and known vulnerabilities.

Alternatives to werkzeug

Other PyPI packages we've checked

Browse all checked packages →

werkzeug is one package. What about the other hundreds in your tree?

Paste your own requirements.txt into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.

Data from the PyPI registry & OSV.dev · snapshot generated 2026-09-07 · scores are deterministic and recomputed on each refresh.