Search CVE reports


Toggle filters

1 – 10 of 161 results


CVE-2026-4292

Low priority
Needs evaluation

Privilege abuse in ModelAdmin.list_editable

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-4277

Low priority
Needs evaluation

Privilege abuse in GenericInlineModelAdmin

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-3902

Low priority
Needs evaluation

ASGI header spoofing via underscore/hyphen conflation

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Needs evaluation Needs evaluation Not affected Not affected
Show less packages

CVE-2026-33034

Low priority
Needs evaluation

Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Needs evaluation Ignored Ignored Ignored
Show less packages

CVE-2026-33033

Medium priority
Needs evaluation

Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-25674

Low priority
Needs evaluation

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created...

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-25673

Medium priority
Not affected

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normalization on Windows that is disproportionately slow...

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-1312

Medium priority

Some fixes available 2 of 7

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably...

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed Ignored Ignored Ignored
Show less packages

CVE-2026-1287

Medium priority
Fixed

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with...

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-1285

Medium priority
Fixed

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.chars()` and `Truncator.words()` methods (with `html=True`) and the `truncatechars_html` and `truncatewords_html`...

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed Fixed Fixed Fixed
Show less packages