CVE-2026-48099

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
13/08/2026
Last modified:
14/08/2026

Description

WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4.