Improper Handling of Windows Device Names in Werkzeug - CVE-2025-66221

 

Improper Handling of Windows Device Names in Werkzeug - CVE-2025-66221

Published: December 1, 2025


Vulnerability identifier: #VU118856
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-66221
CWE-ID: CWE-67
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the "safe_join" function allows path segments with Windows device names. A remote attacker can cause reading of the file to hang indefinitely.


Affected software

Werkzeug
watsonx.data
Netezza Appliance
watsonx Code Assistant On Prem
Maximo Application Suite - Predict Component
Maximo Application Suite - Visual Inspection Component
Maximo Application Suite Ai Service
Maximo Application Suite - Location Service for Esri Component
IBM Cloud Pak for Data System
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Maximo Application Suite - Manage Component

How to mitigate CVE-2025-66221

Install updates from vendor's website.

Werkzeug - update to 3.1.4
Netezza Appliance - update to 1.0.1.0 fp278500
IBM Cloud Pak for Data System - update to 1.0.10.0
watsonx.data - update to 2.3.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
watsonx Code Assistant On Prem - update to 5.3.0
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.34, 8.7.28, 9.0.21, 9.1.8
Maximo Application Suite - Predict Component - addressed in versions 8.8.14, 8.9.16, 9.0.13, 9.1.6
Maximo Application Suite - Visual Inspection Component - addressed in versions 9.0.16, 9.1.7
Maximo Application Suite Ai Service - update to 9.1.10
Maximo Application Suite - Location Service for Esri Component - addressed in versions 9.0.6, 9.1.5

External References

Related Security Bulletins