Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

djangoproject — Vulnerabilities & Security Advisories 42

Browse all 42 CVE security advisories affecting djangoproject. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Django is a high-level Python web framework designed to facilitate rapid development of secure and maintainable websites. Its architecture emphasizes reusability and pluggability, allowing developers to build complex applications efficiently. Historically, the framework has been associated with various vulnerability classes, including SQL injection, cross-site scripting (XSS), and remote code execution (RCE), often stemming from improper input validation or misconfigured settings. With 28 Common Vulnerabilities and Exposures (CVEs) currently on record, the project has faced significant scrutiny regarding its security posture. Notable incidents have highlighted risks related to session fixation and denial-of-service attacks, prompting continuous updates to mitigate these threats. The Django Software Foundation actively addresses these issues through regular security releases, ensuring that developers can rely on a robust foundation while adhering to best practices for secure coding and deployment configurations.

Top products by djangoproject: Django daphne
CVE ID Title CVSS Severity Published
CVE-2026-15920 Potential cross-site scripting via URLField values in the admin — Django CWE-83 6.1 Medium 2026-08-04
CVE-2026-15830 Potential denial-of-service vulnerability via nested geometry collections — Django CWE-674 5.3 Medium 2026-08-04
CVE-2026-15337 Potential denial-of-service vulnerability in check_for_language() — Django CWE-789 5.3 Medium 2026-08-04
CVE-2026-15307 Server-side file-write and request forgery via spatial lookups — Django CWE-73 8.8 High 2026-08-04
CVE-2026-53878 Header injection possibility since DomainNameValidator accepted newlines in input — Django CWE-144 6.1 Medium 2026-07-07
CVE-2026-53877 Heap buffer over-read in GDALRaster — Django CWE-805 4.8 Medium 2026-07-07
CVE-2026-48588 Potential exposure of private data via cached Set-Cookie response — Django CWE-524 4.2 Low 2026-07-07
CVE-2026-44546 Header injection via WebSocket upgrade parser differential allows ASGI scope header spoofing — daphne CWE-444 3.7 Low 2026-06-03
CVE-2026-44545 Unbounded WebSocket message and frame sizes can cause unauthenticated remote denial of service — daphne CWE-770 5.3 Medium 2026-06-03
CVE-2026-48587 Potential exposure of private data via whitespace padding in Vary header — Django CWE-1023 3.1 Low 2026-06-03
CVE-2026-35193 Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddleware — Django CWE-524 3.1 Low 2026-06-03
CVE-2026-8404 Potential exposure of private data via case-sensitive Cache-Control directives in UpdateCacheMiddleware — Django CWE-178 3.1 Low 2026-06-03
CVE-2026-7666 Potential unencrypted email transmission via STARTTLS in the SMTP backend — Django CWE-319 3.1 Low 2026-06-03
CVE-2026-6873 Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie — Django CWE-347 3.1 Low 2026-06-03
CVE-2026-35192 Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST — Django CWE-539 7.6 - 2026-05-05
CVE-2026-6907 Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware — Django CWE-524 4.3 Medium 2026-05-05
CVE-2026-5766 Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass — Django CWE-130 5.3 Medium 2026-05-05
CVE-2026-33034 Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass — Django CWE-770 7.5AI High AI 2026-04-07
CVE-2026-33033 Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload — Django CWE-407 5.3AI Medium AI 2026-04-07
CVE-2026-4292 Privilege abuse in ModelAdmin.list_editable — Django CWE-862 9.1AI Critical AI 2026-04-07
CVE-2026-4277 Privilege abuse in GenericInlineModelAdmin — Django CWE-862 9.8AI Critical AI 2026-04-07
CVE-2026-3902 ASGI header spoofing via underscore/hyphen conflation — Django CWE-290 5.3AI Medium AI 2026-04-07
CVE-2026-25674 Potential incorrect permissions on newly created file system objects — Django CWE-362 6.5 - 2026-03-03
CVE-2026-25673 Potential denial-of-service vulnerability in URLField via Unicode normalization on Windows — Django CWE-400 7.5AI High AI 2026-03-03
CVE-2025-14550 Potential denial-of-service vulnerability via repeated headers when using ASGI — Django CWE-407 7.5 - 2026-02-03
CVE-2026-1312 Potential SQL injection via QuerySet.order_by and FilteredRelation — Django CWE-89 9.8 - 2026-02-03
CVE-2026-1287 Potential SQL injection in column aliases via control characters — Django CWE-89 9.8 - 2026-02-03
CVE-2026-1285 Potential denial-of-service vulnerability in django.utils.text.Truncator HTML methods — Django CWE-407 7.5 - 2026-02-03
CVE-2026-1207 Potential SQL injection via raster lookups on PostGIS — Django CWE-89 9.8 - 2026-02-03
CVE-2025-13473 Username enumeration through timing difference in mod_wsgi authentication handler — Django CWE-208 3.7 - 2026-02-03

This page lists every published CVE security advisory associated with djangoproject. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.