github.com
https://github.com/mar10/wsgidav CVE-2026-48099
HIGH
WsgiDAV encoded dot segments can escape filesystem share roots
Record summary
CVE-2026-48099 has a selected CVSS score of 7.1 (high).
Description
WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4.
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
wsgidavBrowse mar10 / wsgidav | CVE List | < 4.3.4 | affected |
wsgidavBrowse PyPI / wsgidav | GitHub Advisory | Before 4.3.4 · Fixed in 4.3.4 | affected |
References
4github.com
https://github.com/mar10/wsgidav/commit/f894ed8656d7bdd7438ab8148c5a02546cb15183 github.comConfirmation
https://github.com/mar10/wsgidav/security/advisories/GHSA-wxq4-cc2q-338q github.com
https://github.com/pypa/advisory-database/tree/main/vulns/wsgidav/PYSEC-2026-3428.yaml