Vulnerability index

Browse CVEs

129 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Django HIGH 8.8
CVE-2026-15307

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as…

No fix yet
Fix from $1,950 2026-08-04
Django MEDIUM 6.1
CVE-2026-15920

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values …

No fix yet
Fix from $1,600 2026-08-04
Django MEDIUM 5.3
CVE-2026-15337

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential d…

No fix yet
Fix from $1,600 2026-08-04
Django MEDIUM 5.3
CVE-2026-15830

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potentia…

No fix yet
Fix from $1,600 2026-08-04
Django MEDIUM 6.1
CVE-2026-53878

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless us…

Fix: 5.2.16 / 6.0.7+
Fix from $1,600 2026-07-07
Django MEDIUM 5.3
CVE-2026-48588

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses th…

Fix: 5.2.16 / 6.0.7+
Fix from $1,600 2026-07-07
Django MEDIUM 5.3
CVE-2026-8404

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `C…

Fix: 5.2.15 / 6.0.6+
Fix from $1,600 2026-06-03
Django MEDIUM 5.3
CVE-2026-48587

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or …

Fix: 5.2.15 / 6.0.6+
Fix from $1,600 2026-06-03
Daphne HIGH 7.5
CVE-2026-44545

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both va…

Fix: 4.2.2+
Fix from $1,950 2026-06-03
Daphne MEDIUM 5.3
CVE-2026-44546

daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processing. Twiste…

Fix: 4.2.2+
Fix from $1,600 2026-06-03
Django MEDIUM 5.3
CVE-2026-6907

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where …

Fix: 5.2.14 / 6.0.5+
Fix from $1,600 2026-05-05
Django MEDIUM 5.3
CVE-2026-5766

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the…

Fix: 5.2.14 / 6.0.5+
Fix from $1,600 2026-05-05
Django MEDIUM 6.5
CVE-2026-35192

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION…

Fix: 5.2.14 / 6.0.5+
Fix from $1,600 2026-05-05
Django CRITICAL 9.8
CVE-2026-4277

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated o…

Fix: 4.2.30 / 5.2.13+
Fix from $2,300 2026-04-07
Django HIGH 7.5
CVE-2026-3902

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exp…

Fix: 4.2.30 / 5.2.13+
Fix from $1,950 2026-04-07
Django HIGH 7.5
CVE-2026-33034

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` h…

Fix: 4.2.30 / 5.2.13+
Fix from $1,950 2026-04-07
Django MEDIUM 6.5
CVE-2026-33033

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote attackers to degrade performan…

Fix: 4.2.30 / 5.2.13+
Fix from $1,600 2026-04-07
Django HIGH 7.5
CVE-2026-25673

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit(…

Fix: 4.2.29 / 5.2.12+
Fix from $1,950 2026-03-03
Django HIGH 7.5
CVE-2026-1285

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.chars()` and `Truncator.words()` …

Fix: 4.2.28 / 5.2.11+
Fix from $1,950 2026-02-03
Django MEDIUM 5.4
CVE-2026-1207EPSS 13%

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS…

Fix: 4.2.28 / 5.2.11+
Fix from $1,600 2026-02-03
Django MEDIUM 5.4
CVE-2026-1287

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column alias…

Fix: 4.2.28 / 5.2.11+
Fix from $1,600 2026-02-03
Django MEDIUM 5.4
CVE-2026-1312

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column a…

Fix: 4.2.28 / 5.2.11+
Fix from $1,600 2026-02-03
Django HIGH 7.5
CVE-2025-14550

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote attacker to cause a potential de…

Fix: 4.2.28 / 5.2.11+
Fix from $1,950 2026-02-03
Django MEDIUM 5.3
CVE-2025-13473

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers.modwsgi.check_password()` fu…

Fix: 4.2.28 / 5.2.11+
Fix from $1,600 2026-02-03
Django HIGH 7.5
CVE-2025-64460

An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. Algorithmic complexity in `django.core.serializers.xml_seriali…

Fix: 4.2.27 / 5.1.15+
Fix from $1,950 2025-12-02
Django CRITICAL 9.1
CVE-2025-64459EPSS 19%

An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `Qu…

Fix: 4.2.26 / 5.1.14+
Fix from $2,300 2025-11-05
Django HIGH 7.5
CVE-2025-64458

An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is slow on Windows. As a conseque…

Fix: 4.2.26 / 5.1.14+
Fix from $1,950 2025-11-05
Django MEDIUM 6.5
CVE-2025-59682

An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by th…

Fix: 4.2.25 / 5.1.13+
Fix from $1,600 2025-10-01
Django CRITICAL 9.8
CVE-2025-59681

An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggrega…

Fix: 4.2.25 / 5.1.13+
Fix from $2,300 2025-10-01
Django HIGH 8.1
CVE-2025-57833EPSS 16%

An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column …

Fix: 4.2.24 / 5.1.12+
Fix from $1,950 2025-09-03