CODERED VTA

openSUSE Patches Six Werkzeug Flaws in Tumbleweed Python Packages

Medium
Hands on a laptop keyboard
Photo by Markus Spiske on Unsplash

openSUSE has published advisory openSUSE-SU-2026:11943-1, a moderate-rated update that brings the Werkzeug package on openSUSE Tumbleweed to version 3.1.9-1.1. The release closes six vulnerabilities carried in earlier builds on the distribution GA media: CVE-2019-14806, CVE-2023-25577, CVE-2023-46136, CVE-2024-34069, CVE-2024-49767 and CVE-2026-102598. Both python313-Werkzeug and python314-Werkzeug move to the same fixed version. Werkzeug is the WSGI utility library underneath Flask and many other Python web applications, so the exposure follows wherever those services run.

The advisory does not publish exploitation details for any of the six issues, so what is known comes from the scoring the vendor assigned. Three flaws are rated 7.5: CVE-2023-25577 and CVE-2023-46136 are remote, unauthenticated availability issues requiring no user interaction, while CVE-2024-34069 requires user interaction and high attack complexity but carries full confidentiality, integrity and availability impact. CVE-2019-14806 is scored 6.2 and needs local access, affecting confidentiality only. CVE-2024-49767 and CVE-2026-102598 both score 5.3 under CVSS v3.1 and carry limited availability impact, rising to 6.9 and 6.3 respectively under CVSS v4.0.

The weight here lies in how broadly Werkzeug is deployed rather than in any single flaw. Tumbleweed is a rolling release, so systems that have not synchronised recently continue to carry the older package. Measured exploitation probability over the next 30 days is low across the set: FIRST EPSS places CVE-2024-34069 at 3.4 percent, CVE-2019-14806 at 2.3 percent, CVE-2023-25577 at 1.4 percent, CVE-2023-46136 and CVE-2024-49767 at 1.1 percent each, and CVE-2026-102598 at 0.4 percent. None of the six appear in the CISA Known Exploited Vulnerabilities catalogue.

Attack Surface

Web Application, Server OS

Tactics

Initial Access, Impact

Techniques

  • T1190 – Exploit Public-Facing Application
  • T1499 – Endpoint Denial of Service
  • T1499.003 – Application Exhaustion Flood

SuperPRO's Threat Countermeasures Procedures

  1. Apply openSUSE-SU-2026:11943-1 on openSUSE Tumbleweed hosts by running 'zypper refresh && zypper up python313-Werkzeug python314-Werkzeug' so both packages reach version 3.1.9-1.1.
  2. Inventory affected systems with 'rpm -qa | grep -i werkzeug' and flag any host still reporting a python313-Werkzeug or python314-Werkzeug build older than 3.1.9-1.1 from the Tumbleweed GA media.
  3. Check Werkzeug copies that RPM does not manage – run 'pip list | grep -i Werkzeug' inside every virtualenv and container image, and pin 'Werkzeug>=3.1.9' in requirements.txt and Pipfile before rebuilding.
  4. Confirm the Werkzeug development server and its interactive debugger are not reachable in production: run Flask with debug=False, do not bind werkzeug.serving.run_simple to 0.0.0.0, and serve through gunicorn or uWSGI behind a reverse proxy instead.
  5. Cap form and file handling in front of Werkzeug to limit resource-exhaustion conditions – set MAX_CONTENT_LENGTH and max_form_parts in Flask configuration, and enforce client_max_body_size and client_body_timeout in nginx for the same virtual hosts.
  6. Alert on availability symptoms against Flask or Werkzeug endpoints, specifically sustained gunicorn or uWSGI worker saturation, repeated worker timeouts, and bursts of multipart POST requests with abnormally high part counts to a single URI.

Source

Code Red Cyber / VTA – coderedcyber.ai