以下是对该漏洞描述信息的中文翻译: --- 在 Django 6.1 至 6.1.2 之前、6.0 至 6.0.9 之前以及 5.2 至 5.2.18 之前的版本中发现了一个安全问题。 方法将提交表单的实例中主键的存在作为该实例属于表单集所限制查询集的证据。如果一个对象不在该查询集中,它将被表示为一个新构建的实例,而该实例的主键仍可以从提交的数据中填充,前提是模型的主键是表单接受的一个字段(例如 或用作内联表单集模型主键的父链接),或者是包含在表单字段中的自然主键或 UUID 主键。这允许一个被授权提交此类表单集的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| djangoproject | Django | 6.1 ~ 6.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87890 | 5.3 MEDIUM | Potential request forgery via spatial lookup byte values |
| CVE-2026-77050 | 5.3 MEDIUM | Potential denial-of-service vulnerability in get_supported_language_variant() |
| CVE-2026-84429 | 5.3 MEDIUM | Potential denial-of-service vulnerability in HTTP header parsing |
No comments yet