vciy

CVEs we hold for Djangoproject

Records whose assigning authority named Djangoproject as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-8404Potential exposure of private data via case-sensitive Cache-Control directives in UpdateCacheMiddlewaredjangoproject Django
CVE-2026-7666Potential unencrypted email transmission via STARTTLS in the SMTP backenddjangoproject Django
CVE-2026-6907Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddlewaredjangoproject Django
CVE-2026-6873Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookiedjangoproject Django
CVE-2026-5766Potential denial-of-service vulnerability in ASGI requests via file upload limit bypassdjangoproject Django
CVE-2026-53878Header injection possibility since DomainNameValidator accepted newlines in inputdjangoproject Django
CVE-2026-53877Heap buffer over-read in GDALRasterdjangoproject Django
CVE-2026-48588Potential exposure of private data via cached Set-Cookie responsedjangoproject Django
CVE-2026-48587Potential exposure of private data via whitespace padding in Vary headerdjangoproject Django
CVE-2026-44546Header injection via WebSocket upgrade parser differential allows ASGI scope header spoofingdjangoproject daphne
CVE-2026-44545Unbounded WebSocket message and frame sizes can cause unauthenticated remote denial of servicedjangoproject daphne
CVE-2026-4292Privilege abuse in ModelAdmin.list_editabledjangoproject Django
CVE-2026-4277Privilege abuse in GenericInlineModelAdmindjangoproject Django
CVE-2026-3902ASGI header spoofing via underscore/hyphen conflationdjangoproject Django
CVE-2026-35193Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddlewaredjangoproject Django
CVE-2026-35192Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUESTdjangoproject Django
CVE-2026-33034Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypassdjangoproject Django
CVE-2026-33033Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file uploaddjangoproject Django
CVE-2026-25674Potential incorrect permissions on newly created file system objectsdjangoproject Django
CVE-2026-25673Potential denial-of-service vulnerability in URLField via Unicode normalization on Windowsdjangoproject Django
CVE-2026-15920Potential cross-site scripting via URLField values in the admindjangoproject Django
CVE-2026-15830Potential denial-of-service vulnerability via nested geometry collectionsdjangoproject Django
CVE-2026-15337Potential denial-of-service vulnerability in check_for_language()djangoproject Django
CVE-2026-15307Server-side file-write and request forgery via spatial lookupsdjangoproject Django
CVE-2026-1312Potential SQL injection via QuerySet.order_by and FilteredRelationdjangoproject Django
CVE-2026-1287Potential SQL injection in column aliases via control charactersdjangoproject Django
CVE-2026-1285Potential denial-of-service vulnerability in django.utils.text.Truncator HTML methodsdjangoproject Django
CVE-2026-1207Potential SQL injection via raster lookups on PostGISdjangoproject Django
CVE-2025-64460Potential denial-of-service vulnerability in XML serializer text extractiondjangoproject Django
CVE-2025-64459Potential SQL injection via _connector keyword argument in QuerySet and Q objectsdjangoproject Django
CVE-2025-64458Potential denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windowsdjangoproject Django
CVE-2025-59682no title helddjangoproject Django
CVE-2025-59681no title helddjangoproject Django
CVE-2025-57833no title helddjangoproject Django
CVE-2025-48432no title helddjangoproject Django
CVE-2025-32873no title helddjangoproject Django
CVE-2025-27556no title helddjangoproject Django
CVE-2025-26699no title helddjangoproject Django
CVE-2025-14550Potential denial-of-service vulnerability via repeated headers when using ASGIdjangoproject asgiref
CVE-2025-13473Username enumeration through timing difference in mod_wsgi authentication handlerdjangoproject Django
CVE-2025-13372Potential SQL injection in FilteredRelation column aliases on PostgreSQLdjangoproject Django
CVE-2024-56374no title helddjangoproject Django

42 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.