Improper Handling of Windows Device Names Affecting superset-fips-6.1 package, versions <6.1.0-r9


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.37% (29th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-SUPERSETFIPS61-20541692
  • published7 Oct 2026
  • disclosed29 Sept 2026

Introduced: 29 Sep 2026

NewCVE-2026-102598  (opens in a new tab)
CWE-67  (opens in a new tab)

How to fix?

Upgrade Chainguard superset-fips-6.1 to version 6.1.0-r9 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream superset-fips-6.1 package and not the superset-fips-6.1 package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first removing an empty NTFS ADS marker. The trigger is that an application runs on Windows with NTFS and serves a user-specified path ending in a special device name such as NUL:. The attack mechanism is that a requested path ends in a Windows special device name with an empty ADS marker. The impact is that the special device opens successfully and the file read hangs indefinitely. This issue is fixed in version 3.1.9.

CVSS Base Scores

version 3.1