CVEs we hold for Djangoproject
Records whose assigning authority named Djangoproject as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-8404Potential exposure of private data via case-sensitive Cache-Control directives in UpdateCacheMiddlewaredjangoproject Django
CVE-2026-7666Potential unencrypted email transmission via STARTTLS in the SMTP backenddjangoproject Django
CVE-2026-6907Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddlewaredjangoproject Django
CVE-2026-6873Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookiedjangoproject Django
CVE-2026-5766Potential denial-of-service vulnerability in ASGI requests via file upload limit bypassdjangoproject Django
CVE-2026-53878Header injection possibility since DomainNameValidator accepted newlines in inputdjangoproject Django
CVE-2026-48587Potential exposure of private data via whitespace padding in Vary headerdjangoproject Django
CVE-2026-44546Header injection via WebSocket upgrade parser differential allows ASGI scope header spoofingdjangoproject daphne
CVE-2026-44545Unbounded WebSocket message and frame sizes can cause unauthenticated remote denial of servicedjangoproject daphne
CVE-2026-35193Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddlewaredjangoproject Django
CVE-2026-35192Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUESTdjangoproject Django
CVE-2026-33034Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypassdjangoproject Django
CVE-2026-33033Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file uploaddjangoproject Django
CVE-2026-25674Potential incorrect permissions on newly created file system objectsdjangoproject Django
CVE-2026-25673Potential denial-of-service vulnerability in URLField via Unicode normalization on Windowsdjangoproject Django
CVE-2026-15830Potential denial-of-service vulnerability via nested geometry collectionsdjangoproject Django
CVE-2026-1285Potential denial-of-service vulnerability in django.utils.text.Truncator HTML methodsdjangoproject Django
CVE-2025-64460Potential denial-of-service vulnerability in XML serializer text extractiondjangoproject Django
CVE-2025-64459Potential SQL injection via _connector keyword argument in QuerySet and Q objectsdjangoproject Django
CVE-2025-64458Potential denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windowsdjangoproject Django
CVE-2025-14550Potential denial-of-service vulnerability via repeated headers when using ASGIdjangoproject asgiref
CVE-2025-13473Username enumeration through timing difference in mod_wsgi authentication handlerdjangoproject Django
CVE-2025-13372Potential SQL injection in FilteredRelation column aliases on PostgreSQLdjangoproject Django
42 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.