{"apiVersion":"1.0","identifier":"CVE-2026-48099","description":"WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4.","publishedAt":"2026-08-13T20:17:22","lastModifiedAt":"2026-08-14T17:18:19","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-48099","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L","epssProbability":0.00331,"riskScore":0.73,"affectedProduct":"WsgiDAV","affectedVersions":"<=4.3.3","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-48099","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-48099","en":"https://www.redsauce.net/en/cves/CVE-2026-48099","fr":"https://www.redsauce.net/fr/cves/CVE-2026-48099","pt":"https://www.redsauce.net/pt/cves/CVE-2026-48099","de":"https://www.redsauce.net/de/cves/CVE-2026-48099","sk":"https://www.redsauce.net/sk/cves/CVE-2026-48099","el":"https://www.redsauce.net/el/cves/CVE-2026-48099"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-48099"}}