Django security incidents

Recent advisories touching Django apps — searchable, enriched with exploit probability and affected versions.

HIGHPyPI

django CMS: Structure endpoint bypasses page-view permission

django CMS: Structure endpoint bypasses page-view permission

django-cms: before 5.0.8

1 day ago
HIGHPyPI

django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)

django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)

django-cms: before 5.0.9

1 day ago
MEDIUMPyPI

Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`

Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`

djangorestframework: before 3.17.2

1 day ago
MEDIUMPyPI

django CMS: Stored XSS in edit-mode plugin exception rendering

django CMS: Stored XSS in edit-mode plugin exception rendering

django-cms: 5.0.8 → 5.0.9

1 day ago
MEDIUMPyPI

Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests

Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests

djangorestframework: before 3.17.2

1 day ago
MEDIUMPyPI

django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

django-cms: before 5.0.8

1 day ago
MEDIUMPyPI

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django-cms: before 5.0.9

1 day ago
HIGHPyPI

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django-cms: before 5.0.8

1 day ago
HIGHPyPI

django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

django-cms: before 5.0.8

1 day ago
MEDIUMPyPI

Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`

Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`

djangorestframework: before 3.17.2

1 week ago
MEDIUMPyPI

Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests

Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests

djangorestframework: before 3.17.2

1 week ago
MEDIUMPyPI

django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

django-cms: before 5.0.8

2 weeks ago
HIGHPyPI

django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

django-cms: before 5.0.8

2 weeks ago
MEDIUMPyPI

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django-cms: before 5.0.9

3 weeks ago
HIGHPyPI

django CMS: Structure endpoint bypasses page-view permission

django CMS: Structure endpoint bypasses page-view permission

django-cms: before 5.0.8

3 weeks ago
HIGHPyPI

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django-cms: before 5.0.8

3 weeks ago
HIGHPyPI

django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)

django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)

django-cms: before 5.0.9

3 weeks ago
MEDIUMPyPI

django CMS: Stored XSS in edit-mode plugin exception rendering

django CMS: Stored XSS in edit-mode plugin exception rendering

django-cms: 5.0.8 → 5.0.9

3 weeks ago
HIGHPyPI

MobSF's CSRF checks not enforced after Django migration

MobSF's CSRF checks not enforced after Django migration

mobsf: before 4.5.1

3 weeks ago
HIGHnpm

@rhinostone/swig: arbitrary local file read via include/extends path traversal

@rhinostone/swig: arbitrary local file read via include/extends path traversal

3 weeks ago
HIGHPyPI

MobSF's CSRF checks not enforced after Django migration

MobSF's CSRF checks not enforced after Django migration

mobsf: before 4.5.1

3 weeks ago
UNKNOWNPyPI

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected. Ea

django: before 5.2.17

1 month ago
MEDIUMPyPI

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()`

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue.

django: 5.2 → 5.2.16

2 months ago
UNKNOWNPyPI

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-read

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue

django: 5.2 → 5.2.16

2 months ago
MEDIUMPyPI

Django: DomainNameValidator permits newline characters that may enable HTTP header injection

Django: DomainNameValidator permits newline characters that may enable HTTP header injection

django: before 5.2.16

2 months ago
MEDIUMPyPI

Django: cache middleware may expose private responses when unrelated request cookies are present

Django: cache middleware may expose private responses when unrelated request cookies are present

django: before 5.2.16

2 months ago
MEDIUMPyPI

Django: GDALRaster may over-read heap memory when constructed from bytes

Django: GDALRaster may over-read heap memory when constructed from bytes

django: before 5.2.16

2 months ago
UNKNOWNPyPI

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlin

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.

django: 5.2 → 5.2.16

2 months ago
MEDIUMPyPI

Django: has_vary_header may expose cached responses when Vary values contain whitespace

Django: has_vary_header may expose cached responses when Vary values contain whitespace

django: before 5.2.15

3 months ago
MEDIUMPyPI

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Djan

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to than

django: 5.2 → 5.2.15

3 months ago
MEDIUMPyPI

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and salt argument), which allows a remote attacker to use a cookie in a context different from the one where it was signed, via distinct `(name, salt)` pairs that produce the same concatenation. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affec

django: 5.2 → 5.2.15

3 months ago
MEDIUMPyPI

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank A

django: 5.2 → 5.2.15

3 months ago
MEDIUMPyPI

Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary

Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary

django: 5.2.0 → 5.2.15

3 months ago
MEDIUMPyPI

Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling

Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling

django: before 5.2.15

3 months ago
MEDIUMPyPI

Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake

Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake

django: 5.2 → 5.2.15

3 months ago
UNKNOWNPyPI

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to

django: 5.2 → 5.2.15

3 months ago
MEDIUMPyPI

Django: signed cookies are vulnerable to salt namespace collisions

Django: signed cookies are vulnerable to salt namespace collisions

django: before 5.2.15

3 months ago
MEDIUMPyPI

Django Uses Cache Containing Sensitive Information

Django Uses Cache Containing Sensitive Information

django: 6.0 → 6.0.5

4 months ago
MEDIUMPyPI

Django has an Improper Handling of Length Parameter Inconsistency

Django has an Improper Handling of Length Parameter Inconsistency

django: 6.0 → 6.0.5

4 months ago
LOWPyPI

Django Uses Persistent Cookies Containing Sensitive Information

Django Uses Persistent Cookies Containing Sensitive Information

django: 6.0 → 6.0.5

4 months ago
HIGHPyPI

Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit

Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit

django: 6.0 → 6.0.4

5 months ago
MEDIUMPyPI

Django vulnerable to privilege abuse in ModelAdmin.list_editable

Django vulnerable to privilege abuse in ModelAdmin.list_editable

django: 6.0 → 6.0.4

5 months ago
HIGHPyPI

Django has potential DoS via MultiPartParser through crafted multipart uploads

Django has potential DoS via MultiPartParser through crafted multipart uploads

django: 6.0 → 6.0.4

5 months ago
HIGHPyPI

Django vulnerable to ASGI header spoofing via underscore/hyphen conflation

Django vulnerable to ASGI header spoofing via underscore/hyphen conflation

django: 6.0 → 6.0.4

5 months ago
LOWPyPI

Django vulnerable to privilege abuse in GenericInlineModelAdmin

Django vulnerable to privilege abuse in GenericInlineModelAdmin

django: 6.0 → 6.0.4

5 months ago
MEDIUMPyPI

Django has a Race Condition vulnerability

Django has a Race Condition vulnerability

django: 6.0 → 6.0.3

6 months ago
HIGHPyPI

Django vulnerable to Uncontrolled Resource Consumption

Django vulnerable to Uncontrolled Resource Consumption

django: 6.0 → 6.0.3

6 months ago
HIGHPyPI

Django has an SQL Injection issue

Django has an SQL Injection issue

django: 6.0a1 → 6.0.2

7 months ago
HIGHPyPI

Django has an SQL Injection issue

Django has an SQL Injection issue

django: 6.0a1 → 6.0.2

7 months ago
LOWPyPI

Django has Observable Timing Discrepancy

Django has Observable Timing Discrepancy

django: 6.0a1 → 6.0.2

7 months ago
MEDIUMPyPI

Django has an SQL Injection issue

Django has an SQL Injection issue

django: 6.0a1 → 6.0.2

7 months ago
LOWPyPI

Django has Inefficient Algorithmic Complexity

Django has Inefficient Algorithmic Complexity

django: 6.0a1 → 6.0.2

7 months ago
LOWPyPI

Django has Inefficient Algorithmic Complexity

Django has Inefficient Algorithmic Complexity

django: 6.0a1 → 6.0.2

7 months ago
MODERATEPyPI

Django is vulnerable to DoS via XML serializer text extraction

Django is vulnerable to DoS via XML serializer text extraction

django: 5.2a1 → 5.2.9

9 months ago
MEDIUMPyPI

Django is vulnerable to SQL injection in column aliases

Django is vulnerable to SQL injection in column aliases

django: 5.2a1 → 5.2.9

9 months ago
HIGHPyPI

Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

django: 5.2a1 → 5.2.8

10 months ago
HIGHPyPI

Django vulnerable to SQL injection in column aliases

Django vulnerable to SQL injection in column aliases

django: 4.2 → 4.2.25

11 months ago
MEDIUMPyPI

Django vulnerable to partial directory traversal via archives

Django vulnerable to partial directory traversal via archives

django: 4.2 → 4.2.25

11 months ago
HIGHPyPI

Django is subject to SQL injection through its column aliases

Django is subject to SQL injection through its column aliases

django: before 4.2.24

1 year ago
MEDIUMPyPI

Django Improper Output Neutralization for Logs vulnerability

Django Improper Output Neutralization for Logs vulnerability

django: 5.2 → 5.2.2

1 year ago
HIGHPyPI

Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking

Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking

django-select2: before 8.4.1

1 year ago
MEDIUMPyPI

Django has a denial-of-service possibility in strip_tags()

Django has a denial-of-service possibility in strip_tags()

django: 4.2 → 4.2.21

1 year ago
MEDIUMPyPI

Django vulnerable to Allocation of Resources Without Limits or Throttling

Django vulnerable to Allocation of Resources Without Limits or Throttling

django: 4.2 → 4.2.20

1 year ago
MEDIUMPyPI

Django has a potential denial-of-service vulnerability in IPv6 validation

Django has a potential denial-of-service vulnerability in IPv6 validation

django: 5.1 → 5.1.5

1 year ago
HIGHPyPI

Django denial-of-service in django.utils.html.strip_tags()

Django denial-of-service in django.utils.html.strip_tags()

django: 5.1.0 → 5.1.4

1 year ago
CRITICALPyPI

Django SQL injection in HasKey(lhs, rhs) on Oracle

Django SQL injection in HasKey(lhs, rhs) on Oracle

django: 5.0.0 → 5.0.10

1 year ago
HIGHPyPI

Django vulnerable to Denial of Service

Django vulnerable to Denial of Service

django: 5.0 → 5.0.7

2 years ago
MEDIUMPyPI

Django vulnerable to user enumeration attack

Django vulnerable to user enumeration attack

django: 5.0 → 5.0.7

2 years ago
HIGHPyPI

Django vulnerable to Denial of Service

Django vulnerable to Denial of Service

django: 4.2 → 4.2.14

2 years ago
HIGHPyPI

Django Path Traversal vulnerability

Django Path Traversal vulnerability

django: 5.0 → 5.0.7

2 years ago
MEDIUMnpm

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

TinyMCE: before 5.11.0

2 years ago
MEDIUMnpm

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

TinyMCE: before 5.11.0

2 years ago
MEDIUMPyPI

social-auth-app-django affected by Improper Handling of Case Sensitivity

social-auth-app-django affected by Improper Handling of Case Sensitivity

social-auth-app-django: before 5.4.1

2 years ago
HIGHPyPI

Regular expression denial-of-service in Django

Regular expression denial-of-service in Django

django: 3.2 → 3.2.25

2 years ago
HIGHPyPI

Django denial-of-service attack in the intcomma template filter

Django denial-of-service attack in the intcomma template filter

django: 3.2 → 3.2.24

2 years ago
HIGHGo

Django Template Engine Vulnerable to XSS

Django Template Engine Vulnerable to XSS

2 years ago
MEDIUMPyPI

Incorrect signature verification in django-ses

Incorrect signature verification in django-ses

django-ses: before 3.5.0

3 years ago
HIGHPyPI

User passwords are stored in clear text in the Django session

User passwords are stored in clear text in the Django session

django-two-factor-auth: before 1.12

6 years ago
CRITICALPyPI

Improper Verification of Cryptographic Signature in django-rest-registration

Improper Verification of Cryptographic Signature in django-rest-registration

django-rest-registration: 0.2.0 → 0.5.0

7 years ago

Tooling for Django

SnykScan your dependencies in CI and fix this vulnerability.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.