Django security incidents
Recent advisories touching Django apps — searchable, enriched with exploit probability and affected versions.
django CMS: Structure endpoint bypasses page-view permission
django CMS: Structure endpoint bypasses page-view permission
django-cms: before 5.0.8
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
django-cms: before 5.0.9
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
djangorestframework: before 3.17.2
django CMS: Stored XSS in edit-mode plugin exception rendering
django CMS: Stored XSS in edit-mode plugin exception rendering
django-cms: 5.0.8 → 5.0.9
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
djangorestframework: before 3.17.2
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django-cms: before 5.0.8
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django-cms: before 5.0.9
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
django-cms: before 5.0.8
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
django-cms: before 5.0.8
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
djangorestframework: before 3.17.2
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
djangorestframework: before 3.17.2
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django-cms: before 5.0.8
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
django-cms: before 5.0.8
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django-cms: before 5.0.9
django CMS: Structure endpoint bypasses page-view permission
django CMS: Structure endpoint bypasses page-view permission
django-cms: before 5.0.8
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
django-cms: before 5.0.8
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
django-cms: before 5.0.9
django CMS: Stored XSS in edit-mode plugin exception rendering
django CMS: Stored XSS in edit-mode plugin exception rendering
django-cms: 5.0.8 → 5.0.9
MobSF's CSRF checks not enforced after Django migration
MobSF's CSRF checks not enforced after Django migration
mobsf: before 4.5.1
@rhinostone/swig: arbitrary local file read via include/extends path traversal
@rhinostone/swig: arbitrary local file read via include/extends path traversal
MobSF's CSRF checks not enforced after Django migration
MobSF's CSRF checks not enforced after Django migration
mobsf: before 4.5.1
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected. Ea
django: before 5.2.17
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()`
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue.
django: 5.2 → 5.2.16
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-read
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue
django: 5.2 → 5.2.16
Django: DomainNameValidator permits newline characters that may enable HTTP header injection
Django: DomainNameValidator permits newline characters that may enable HTTP header injection
django: before 5.2.16
Django: cache middleware may expose private responses when unrelated request cookies are present
Django: cache middleware may expose private responses when unrelated request cookies are present
django: before 5.2.16
Django: GDALRaster may over-read heap memory when constructed from bytes
Django: GDALRaster may over-read heap memory when constructed from bytes
django: before 5.2.16
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlin
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
django: 5.2 → 5.2.16
Django: has_vary_header may expose cached responses when Vary values contain whitespace
Django: has_vary_header may expose cached responses when Vary values contain whitespace
django: before 5.2.15
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Djan
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to than
django: 5.2 → 5.2.15
An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in
An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and salt argument), which allows a remote attacker to use a cookie in a context different from the one where it was signed, via distinct `(name, salt)` pairs that produce the same concatenation. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affec
django: 5.2 → 5.2.15
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank A
django: 5.2 → 5.2.15
Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary
Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary
django: 5.2.0 → 5.2.15
Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
django: before 5.2.15
Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
django: 5.2 → 5.2.15
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to
django: 5.2 → 5.2.15
Django: signed cookies are vulnerable to salt namespace collisions
Django: signed cookies are vulnerable to salt namespace collisions
django: before 5.2.15
Django Uses Cache Containing Sensitive Information
Django Uses Cache Containing Sensitive Information
django: 6.0 → 6.0.5
Django has an Improper Handling of Length Parameter Inconsistency
Django has an Improper Handling of Length Parameter Inconsistency
django: 6.0 → 6.0.5
Django Uses Persistent Cookies Containing Sensitive Information
Django Uses Persistent Cookies Containing Sensitive Information
django: 6.0 → 6.0.5
Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit
Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit
django: 6.0 → 6.0.4
Django vulnerable to privilege abuse in ModelAdmin.list_editable
Django vulnerable to privilege abuse in ModelAdmin.list_editable
django: 6.0 → 6.0.4
Django has potential DoS via MultiPartParser through crafted multipart uploads
Django has potential DoS via MultiPartParser through crafted multipart uploads
django: 6.0 → 6.0.4
Django vulnerable to ASGI header spoofing via underscore/hyphen conflation
Django vulnerable to ASGI header spoofing via underscore/hyphen conflation
django: 6.0 → 6.0.4
Django vulnerable to privilege abuse in GenericInlineModelAdmin
Django vulnerable to privilege abuse in GenericInlineModelAdmin
django: 6.0 → 6.0.4
Django has a Race Condition vulnerability
Django has a Race Condition vulnerability
django: 6.0 → 6.0.3
Django vulnerable to Uncontrolled Resource Consumption
Django vulnerable to Uncontrolled Resource Consumption
django: 6.0 → 6.0.3
Django has an SQL Injection issue
Django has an SQL Injection issue
django: 6.0a1 → 6.0.2
Django has an SQL Injection issue
Django has an SQL Injection issue
django: 6.0a1 → 6.0.2
Django has Observable Timing Discrepancy
Django has Observable Timing Discrepancy
django: 6.0a1 → 6.0.2
Django has an SQL Injection issue
Django has an SQL Injection issue
django: 6.0a1 → 6.0.2
Django has Inefficient Algorithmic Complexity
Django has Inefficient Algorithmic Complexity
django: 6.0a1 → 6.0.2
Django has Inefficient Algorithmic Complexity
Django has Inefficient Algorithmic Complexity
django: 6.0a1 → 6.0.2
Django is vulnerable to DoS via XML serializer text extraction
Django is vulnerable to DoS via XML serializer text extraction
django: 5.2a1 → 5.2.9
Django is vulnerable to SQL injection in column aliases
Django is vulnerable to SQL injection in column aliases
django: 5.2a1 → 5.2.9
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
django: 5.2a1 → 5.2.8
Django vulnerable to SQL injection in column aliases
Django vulnerable to SQL injection in column aliases
django: 4.2 → 4.2.25
Django vulnerable to partial directory traversal via archives
Django vulnerable to partial directory traversal via archives
django: 4.2 → 4.2.25
Django is subject to SQL injection through its column aliases
Django is subject to SQL injection through its column aliases
django: before 4.2.24
Django Improper Output Neutralization for Logs vulnerability
Django Improper Output Neutralization for Logs vulnerability
django: 5.2 → 5.2.2
Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
django-select2: before 8.4.1
Django has a denial-of-service possibility in strip_tags()
Django has a denial-of-service possibility in strip_tags()
django: 4.2 → 4.2.21
Django vulnerable to Allocation of Resources Without Limits or Throttling
Django vulnerable to Allocation of Resources Without Limits or Throttling
django: 4.2 → 4.2.20
Django has a potential denial-of-service vulnerability in IPv6 validation
Django has a potential denial-of-service vulnerability in IPv6 validation
django: 5.1 → 5.1.5
Django denial-of-service in django.utils.html.strip_tags()
Django denial-of-service in django.utils.html.strip_tags()
django: 5.1.0 → 5.1.4
Django SQL injection in HasKey(lhs, rhs) on Oracle
Django SQL injection in HasKey(lhs, rhs) on Oracle
django: 5.0.0 → 5.0.10
Django vulnerable to Denial of Service
Django vulnerable to Denial of Service
django: 5.0 → 5.0.7
Django vulnerable to user enumeration attack
Django vulnerable to user enumeration attack
django: 5.0 → 5.0.7
Django vulnerable to Denial of Service
Django vulnerable to Denial of Service
django: 4.2 → 4.2.14
Django Path Traversal vulnerability
Django Path Traversal vulnerability
django: 5.0 → 5.0.7
TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option
TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option
TinyMCE: before 5.11.0
TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements
TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements
TinyMCE: before 5.11.0
social-auth-app-django affected by Improper Handling of Case Sensitivity
social-auth-app-django affected by Improper Handling of Case Sensitivity
social-auth-app-django: before 5.4.1
Regular expression denial-of-service in Django
Regular expression denial-of-service in Django
django: 3.2 → 3.2.25
Django denial-of-service attack in the intcomma template filter
Django denial-of-service attack in the intcomma template filter
django: 3.2 → 3.2.24
Django Template Engine Vulnerable to XSS
Django Template Engine Vulnerable to XSS
Incorrect signature verification in django-ses
Incorrect signature verification in django-ses
django-ses: before 3.5.0
User passwords are stored in clear text in the Django session
User passwords are stored in clear text in the Django session
django-two-factor-auth: before 1.12
Improper Verification of Cryptographic Signature in django-rest-registration
Improper Verification of Cryptographic Signature in django-rest-registration
django-rest-registration: 0.2.0 → 0.5.0
Tooling for Django
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.