Django django是Django基金会开源的一个Web应用开发框架。 Django 5.2.17版本之前的5.2版本和6.0.8版本之前的6.0版本存在资源管理错误漏洞,该漏洞源于django.utils.translation.check_for_language()函数在处理大量不同且超长的语言代码时,将其作为键存储在内存缓存中并消耗进程内存,可能导致拒绝服务攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| djangoproject | Django | 6.0< 6.0.8 |
affected |
6.0.8 |
unaffected | ||
5.2< 5.2.17 |
affected | ||
5.2.17 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| djangoproject | Django | 6.0 ~ 6.0.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15307 | 8.8 HIGH | Server-side file-write and request forgery via spatial lookups |
| CVE-2026-15920 | 6.1 MEDIUM | Potential cross-site scripting via URLField values in the admin |
| CVE-2026-15830 | 5.3 MEDIUM | Potential denial-of-service vulnerability via nested geometry collections |
No comments yet