Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Werkzeug >=2.0.0, <3.0.1 has a bug (in some cases, a security bug) that may result in excessive CPU usage and worker timeout when huge file (usually over 50MB) with specific layout is uploaded to MWDB. The issue is when uploaded file contents are meaningful/random at the beginning (contain CR/LF bytes) and then are extensively padded with zeroes. This is common file pattern for bloated malware samples and memory dumps, so it may highly affect performance or even cause a denial of service if MWDB is flooded with such file uploads. References: - https://www.cve.org/CVERecord?id=CVE-2023-46136 - pallets/werkzeug#2801
- Loading branch information