Python/django/1.8.16 A high-level Python web framework that encourages rapid development and clean, pragmatic design.
Repo Link: https://pypi.org/project/django License: BSD
17 Security Vulnerabilities Published date: 2019-01-04T17:50:00Z
CVE: CVE-2018-7537
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs due to a catastrophic backtracking vulnerability in a regular expression. The chars() and words() methods are used to implement the truncatecharshtml and truncatewords html template filters, which were thus vulnerable.
Affected versions: ["1.8.1", "1.8.15", "1.8.17", "1.8.16", "1.8.18", "1.8.6", "1.8.2", "1.8.5", "1.8", "1.8.10", "1.8.13", "1.8.9", "1.8.11", "1.8.8", "1.8.7", "1.8.3", "1.8.12", "1.8.4", "1.8.14", "1.11.1", "1.11.3", "1.11.8", "1.11.9", "1.11.2", "1.11", "1.11.4", "1.11.5", "1.11.7", "1.11.10", "1.11.6", "2.0", "2.0.1", "2.0.2"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
Published date: 2019-01-14T16:20:05Z
CVE: CVE-2019-3498
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.
Affected versions: ["2.1", "2.1.1", "2.1.2", "2.1.3", "2.1.4", "2.0", "2.0.1", "2.0.2", "2.0.3", "2.0.4", "2.0.5", "2.0.6", "2.0.7", "2.0.8", "2.0.9", "1.0.1", "1.0.2", "1.0.3", "1.0.4", "1.1", "1.1.1", "1.1.2", "1.1.3", "1.1.4", "1.10", "1.10.1", "1.10.2", "1.10.3", "1.10.4", "1.10.5", "1.10.6", "1.10.7", "1.10.8", "1.10a1", "1.10b1", "1.10rc1", "1.11", "1.11.1", "1.11.10", "1.11.11", "1.11.12", "1.11.13", "1.11.14", "1.11.15", "1.11.16", "1.11.17", "1.11.2", "1.11.3", "1.11.4", "1.11.5", "1.11.6", "1.11.7", "1.11.8", "1.11.9", "1.11a1", "1.11b1", "1.11rc1", "1.2", "1.2.1", "1.2.2", "1.2.3", "1.2.4", "1.2.5", "1.2.6", "1.2.7", "1.3", "1.3.1", "1.3.2", "1.3.3", "1.3.4", "1.3.5", "1.3.6", "1.3.7", "1.4", "1.4.1", "1.4.10", "1.4.11", "1.4.12", "1.4.13", "1.4.14", "1.4.15", "1.4.16", "1.4.17", "1.4.18", "1.4.19", "1.4.2", "1.4.20", "1.4.21", "1.4.22", "1.4.3", "1.4.4", "1.4.5", "1.4.6", "1.4.7", "1.4.8", "1.4.9", "1.5", "1.5.1", "1.5.10", "1.5.11", "1.5.12", "1.5.2", "1.5.3", "1.5.4", "1.5.5", "1.5.6", "1.5.7", "1.5.8", "1.5.9", "1.6", "1.6.1", "1.6.10", "1.6.11", "1.6.2", "1.6.3", "1.6.4", "1.6.5", "1.6.6", "1.6.7", "1.6.8", "1.6.9", "1.7", "1.7.1", "1.7.10", "1.7.11", "1.7.2", "1.7.3", "1.7.4", "1.7.5", "1.7.6", "1.7.7", "1.7.8", "1.7.9", "1.8", "1.8.1", "1.8.10", "1.8.11", "1.8.12", "1.8.13", "1.8.14", "1.8.15", "1.8.16", "1.8.17", "1.8.18", "1.8.19", "1.8.2", "1.8.3", "1.8.4", "1.8.5", "1.8.6", "1.8.7", "1.8.8", "1.8.9", "1.9", "1.9.1", "1.9.10", "1.9.11", "1.9.12", "1.9.13", "1.9.2", "1.9.3", "1.9.4", "1.9.5", "1.9.6", "1.9.7", "1.9.8", "1.9.9"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
Published date: 2019-01-04T17:50:26Z
CVE: CVE-2017-7233
Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an on success URL. The security check for these redirects (namely django.utils.http.is_safe_url()) considered some numeric URLs safe when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on is_safe_url() to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.
Affected versions: ["1.8", "1.8.1", "1.8.10", "1.8.11", "1.8.12", "1.8.13", "1.8.14", "1.8.15", "1.8.16", "1.8.17", "1.8.2", "1.8.3", "1.8.4", "1.8.5", "1.8.6", "1.8.7", "1.8.8", "1.8.9", "1.9", "1.9.1", "1.9.10", "1.9.11", "1.9.12", "1.9.2", "1.9.3", "1.9.4", "1.9.5", "1.9.6", "1.9.7", "1.9.8", "1.9.9", "1.10", "1.10.1", "1.10.2", "1.10.3", "1.10.4", "1.10.5", "1.10.6"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
Published date: 2026-07-07T15:32:57Z
CVE: CVE-2026-48588
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. UpdateCacheMiddleware and the cache_page() decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue.
Affected versions: ["6.0", "6.0.1", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "6.0.6", "1.4.22", "1.4.7", "1.6.10", "1.9.11", "3.0.7", "1.11.1", "1.4", "1.6.3", "1.8.1", "1.8.15", "1.9rc2", "3.2", "1.0.3", "1.11.24", "1.4.16", "1.4.17", "1.7.11", "1.7.8", "1.7.9", "1.8.17", "1.10rc1", "1.11.14", "1.11.23", "1.2", "1.2.2", "1.3.4", "1.7.10", "1.8.16", "1.8.18", "1.8.6", "1.8a1", "1.8b1", "1.8c1", "2.1.14", "2.1.4", "1.11.27", "1.5.6", "1.6.4", "1.8.2", "1.9", "3.0.3", "1.2.4", "1.7.6", "1.7.7", "1.8.5", "1.8b2", "2.0.3", "2.1.8", "2.1a1", "3.0.6", "1.0.2", "1.1.3", "2.1.15", "3.0.10", "3.0.11", "3.2rc1", "3.1a1", "1.1.4", "1.10.1", "1.11.3", "1.5.3", "1.9b1", "2.1.13", "1.11.18", "1.4.8", "1.8", "2.2.18", "1.0.4", "1.11.22", "1.2.5", "1.4.10", "1.4.12", "1.6.1", "1.8.10", "1.8.13", "2.0", "2.0.1", "2.0.4", "2.0a1", "1.10b1", "1.9.8", "2.2.17", "3.0.9", "1.2.6", "1.3", "1.5.1", "1.5.7", "1.6.11", "1.9.1", "2.2.9", "3.1.7", "1.11.12", "1.11.8", "1.11.9", "1.11rc1", "1.3.7", "1.7.2", "1.8.9", "1.9.9", "2.1.1", "3.1.6", "1.0.1", "1.10", "1.11.26", "1.5.5", "1.6.6", "2.1.3", "2.2.12", "3.0.1", "3.0.14", "3.0.8", "1.11.15", "2.0.5", "2.1.2", "3.0.4", "3.1rc1", "1.4.19", "1.6", "3.1.8", "1.10.8", "1.11.2", "1.4.11", "1.7.1", "1.10.4", "1.4.14", "1.4.20", "1.10.5", "1.10a1", "1.11", "1.11.25", "1.11.4", "1.11.5", "1.4.13", "1.4.3", "1.6.8", "1.10.6", "1.4.5", "1.6.7", "1.8.11", "1.11.7", "1.3.6", "1.11.13", "1.2.3", "1.3.2", "1.4.4", "1.5.8", "1.9.3", "1.9.4", "2.2.15", "3.0", "3.1.2", "3.1.4", "1.8.8", "1.9.12", "2.1.5", "2.2.16", "2.2.8", "3.1.5", "3.2a1", "1.10.2", "1.11.16", "1.11.17", "1.5.4", "1.6.9", "1.1", "1.10.3", "1.10.7", "1.11b1", "1.4.6", "1.5.11", "1.9.13", "2.0.7", "2.2.11", "2.2.2", "3.0.5", "3.1", "1.8.7", "1.9.5", "1.9rc1", "2.0b1", "2.0.6", "2.1.7", "3.0.12", "1.8.3", "1.9a1", "2.1.12", "2.1rc1", "2.2.5", "2.0.2", "2.1.10", "2.2", "3.1.1", "3.1.3", "1.9.7", "2.1.11", "2.2.1", "2.2.14", "2.2.3", "2.2b1", "3.0rc1", "3.1b1", "3.2b1", "1.2.7", "1.5.2", "1.6.5", "1.1.2", "1.4.18", "1.5.10", "1.7.3", "1.7.4", "1.11.20", "1.4.9", "1.5.12", "1.11.29", "1.3.5", "1.4.15", "1.11.21", "1.11.28", "1.11a1", "1.4.1", "1.5.9", "1.7", "1.9.2", "2.0.12", "1.8.12", "2.2.10", "2.2.19", "2.2.6", "3.0.13", "3.0b1", "1.8.4", "2.0.13", "2.2rc1", "1.1.1", "1.11.10", "1.11.11", "1.3.3", "1.4.21", "1.6.2", "1.11.6", "1.2.1", "1.3.1", "1.4.2", "1.5", "1.7.5", "2.1.9", "1.8.19", "1.9.10", "2.0.8", "2.0.9", "2.1", "2.2.20", "2.2.13", "2.2.7", "2.2a1", "3.0.2", "1.8.14", "2.0rc1", "2.1b1", "3.0a1", "1.9.6", "2.0.10", "2.2.4", "2.2.21", "3.2.1", "3.1.9", "2.2.22", "3.2.2", "3.1.10", "3.1.11", "2.2.23", "3.2.3", "2.2.24", "3.1.12", "3.2.4", "3.2.5", "3.1.13", "3.2.6", "3.2.7", "4.0a1", "3.2.8", "4.0b1", "3.2.9", "4.0rc1", "3.2.10", "2.2.25", "3.1.14", "4.0", "4.0.1", "3.2.11", "2.2.26", "3.2.12", "2.2.27", "4.0.2", "4.0.3", "4.0.4", "3.2.13", "2.2.28", "4.1a1", "4.0.5", "4.1b1", "3.2.14", "4.0.6", "4.1rc1", "3.2.15", "4.0.7", "4.1", "4.1.1", "3.2.16", "4.0.8", "4.1.2", "4.1.3", "4.1.4", "4.1.5", "4.2a1", "4.0.9", "3.2.17", "4.1.6", "4.0.10", "3.2.18", "4.1.7", "4.2b1", "4.2rc1", "4.2", "4.1.8", "4.1.9", "4.2.1", "3.2.19", "4.2.2", "4.2.3", "3.2.20", "4.1.10", "4.2.4", "3.2.21", "4.2.5", "4.1.11", "5.0a1", "4.1.12", "3.2.22", "4.2.6", "5.0b1", "3.2.23", "4.1.13", "4.2.7", "5.0rc1", "5.0", "4.2.8", "4.2.9", "5.0.1", "3.2.24", "4.2.10", "5.0.2", "4.2.11", "5.0.3", "3.2.25", "5.0.4", "5.0.5", "4.2.12", "4.2.13", "5.0.6", "5.1a1", "5.1b1", "4.2.14", "5.0.7", "5.1rc1", "5.0.8", "4.2.15", "5.1", "4.2.16", "5.1.1", "5.0.9", "5.1.2", "5.1.3", "5.0.10", "4.2.17", "5.1.4", "5.0.11", "5.1.5", "4.2.18", "5.2a1", "5.0.12", "5.1.6", "4.2.19", "5.2b1", "4.2.20", "5.1.7", "5.0.13", "5.2rc1", "5.1.8", "5.0.14", "5.2", "5.2.1", "4.2.21", "5.1.9", "4.2.22", "5.1.10", "5.2.2", "4.2.23", "5.1.11", "5.2.3", "5.2.4", "5.2.5", "5.1.12", "5.2.6", "4.2.24", "5.1.13", "5.2.7", "4.2.25", "5.1.14", "4.2.26", "5.2.8", "4.2.27", "5.1.15", "5.2.9", "5.2.10", "4.2.28", "5.2.11", "4.2.29", "5.2.12", "4.2.30", "5.2.13", "5.2.14", "5.2.15"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
Published date: 2021-06-10T17:21:00Z
CVE: CVE-2021-33203
Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existence of arbitrary files. Additionally, if (and only if) the default admindocs templates have been customized by application developers to also show file contents, then not only the existence but also the file contents would have been exposed. In other words, there is directory traversal outside of the template root directories.
Affected versions: ["1.4.22", "1.4.7", "1.6.10", "1.9.11", "1.11.1", "1.4", "1.6.3", "1.8.1", "1.8.15", "1.9rc2", "1.0.3", "1.11.24", "1.4.16", "1.4.17", "1.7.11", "1.7.8", "1.7.9", "1.8.17", "1.10rc1", "1.11.14", "1.11.23", "1.2", "1.2.2", "1.3.4", "1.7.10", "1.8.16", "1.8.18", "1.8.6", "1.8a1", "1.8b1", "1.8c1", "2.1.14", "2.1.4", "1.11.27", "1.5.6", "1.6.4", "1.8.2", "1.9", "1.2.4", "1.7.6", "1.7.7", "1.8.5", "1.8b2", "2.0.3", "2.1.8", "2.1a1", "1.0.2", "1.1.3", "2.1.15", "1.1.4", "1.10.1", "1.11.3", "1.5.3", "1.9b1", "2.1.13", "1.11.18", "1.4.8", "1.8", "2.2.18", "1.0.4", "1.11.22", "1.2.5", "1.4.10", "1.4.12", "1.6.1", "1.8.10", "1.8.13", "2.0", "2.0.1", "2.0.4", "2.0a1", "1.10b1", "1.9.8", "2.2.17", "1.2.6", "1.3", "1.5.1", "1.5.7", "1.6.11", "1.9.1", "2.2.9", "1.11.12", "1.11.8", "1.11.9", "1.11rc1", "1.3.7", "1.7.2", "1.8.9", "1.9.9", "2.1.1", "1.0.1", "1.10", "1.11.26", "1.5.5", "1.6.6", "2.1.3", "2.2.12", "1.11.15", "2.0.5", "2.1.2", "1.4.19", "1.6", "1.10.8", "1.11.2", "1.4.11", "1.7.1", "1.10.4", "1.4.14", "1.4.20", "1.10.5", "1.10a1", "1.11", "1.11.25", "1.11.4", "1.11.5", "1.4.13", "1.4.3", "1.6.8", "1.10.6", "1.4.5", "1.6.7", "1.8.11", "1.11.7", "1.3.6", "1.11.13", "1.2.3", "1.3.2", "1.4.4", "1.5.8", "1.9.3", "1.9.4", "2.2.15", "1.8.8", "1.9.12", "2.1.5", "2.2.16", "2.2.8", "1.10.2", "1.11.16", "1.11.17", "1.5.4", "1.6.9", "1.1", "1.10.3", "1.10.7", "1.11b1", "1.4.6", "1.5.11", "1.9.13", "2.0.7", "2.2.11", "2.2.2", "1.8.7", "1.9.5", "1.9rc1", "2.0b1", "2.0.6", "2.1.7", "1.8.3", "1.9a1", "2.1.12", "2.1rc1", "2.2.5", "2.0.2", "2.1.10", "2.2", "1.9.7", "2.1.11", "2.2.1", "2.2.14", "2.2.3", "2.2b1", "1.2.7", "1.5.2", "1.6.5", "1.1.2", "1.4.18", "1.5.10", "1.7.3", "1.7.4", "1.11.20", "1.4.9", "1.5.12", "1.11.29", "1.3.5", "1.4.15", "1.11.21", "1.11.28", "1.11a1", "1.4.1", "1.5.9", "1.7", "1.9.2", "2.0.12", "1.8.12", "2.2.10", "2.2.19", "2.2.6", "1.8.4", "2.0.13", "2.2rc1", "1.1.1", "1.11.10", "1.11.11", "1.3.3", "1.4.21", "1.6.2", "1.11.6", "1.2.1", "1.3.1", "1.4.2", "1.5", "1.7.5", "2.1.9", "1.8.19", "1.9.10", "2.0.8", "2.0.9", "2.1", "2.2.20", "2.2.13", "2.2.7", "2.2a1", "1.8.14", "2.0rc1", "2.1b1", "1.9.6", "2.0.10", "2.2.4", "2.2.21", "2.2.22", "2.2.23"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
Published date: 2026-06-03T15:30:43Z
CVE: CVE-2026-8404
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. django.middleware.cache.UpdateCacheMiddleware in Django does not match Cache-Control response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their Cache-Control directives used uppercase or mixed-case values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmed Badawe for reporting this issue.
Affected versions: ["6.0", "6.0.1", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "1.4.22", "1.4.7", "1.6.10", "1.9.11", "3.0.7", "1.11.1", "1.4", "1.6.3", "1.8.1", "1.8.15", "1.9rc2", "3.2", "1.0.3", "1.11.24", "1.4.16", "1.4.17", "1.7.11", "1.7.8", "1.7.9", "1.8.17", "1.10rc1", "1.11.14", "1.11.23", "1.2", "1.2.2", "1.3.4", "1.7.10", "1.8.16", "1.8.18", "1.8.6", "1.8a1", "1.8b1", "1.8c1", "2.1.14", "2.1.4", "1.11.27", "1.5.6", "1.6.4", "1.8.2", "1.9", "3.0.3", "1.2.4", "1.7.6", "1.7.7", "1.8.5", "1.8b2", "2.0.3", "2.1.8", "2.1a1", "3.0.6", "1.0.2", "1.1.3", "2.1.15", "3.0.10", "3.0.11", "3.2rc1", "3.1a1", "1.1.4", "1.10.1", "1.11.3", "1.5.3", "1.9b1", "2.1.13", "1.11.18", "1.4.8", "1.8", "2.2.18", "1.0.4", "1.11.22", "1.2.5", "1.4.10", "1.4.12", "1.6.1", "1.8.10", "1.8.13", "2.0", "2.0.1", "2.0.4", "2.0a1", "1.10b1", "1.9.8", "2.2.17", "3.0.9", "1.2.6", "1.3", "1.5.1", "1.5.7", "1.6.11", "1.9.1", "2.2.9", "3.1.7", "1.11.12", "1.11.8", "1.11.9", "1.11rc1", "1.3.7", "1.7.2", "1.8.9", "1.9.9", "2.1.1", "3.1.6", "1.0.1", "1.10", "1.11.26", "1.5.5", "1.6.6", "2.1.3", "2.2.12", "3.0.1", "3.0.14", "3.0.8", "1.11.15", "2.0.5", "2.1.2", "3.0.4", "3.1rc1", "1.4.19", "1.6", "3.1.8", "1.10.8", "1.11.2", "1.4.11", "1.7.1", "1.10.4", "1.4.14", "1.4.20", "1.10.5", "1.10a1", "1.11", "1.11.25", "1.11.4", "1.11.5", "1.4.13", "1.4.3", "1.6.8", "1.10.6", "1.4.5", "1.6.7", "1.8.11", "1.11.7", "1.3.6", "1.11.13", "1.2.3", "1.3.2", "1.4.4", "1.5.8", "1.9.3", "1.9.4", "2.2.15", "3.0", "3.1.2", "3.1.4", "1.8.8", "1.9.12", "2.1.5", "2.2.16", "2.2.8", "3.1.5", "3.2a1", "1.10.2", "1.11.16", "1.11.17", "1.5.4", "1.6.9", "1.1", "1.10.3", "1.10.7", "1.11b1", "1.4.6", "1.5.11", "1.9.13", "2.0.7", "2.2.11", "2.2.2", "3.0.5", "3.1", "1.8.7", "1.9.5", "1.9rc1", "2.0b1", "2.0.6", "2.1.7", "3.0.12", "1.8.3", "1.9a1", "2.1.12", "2.1rc1", "2.2.5", "2.0.2", "2.1.10", "2.2", "3.1.1", "3.1.3", "1.9.7", "2.1.11", "2.2.1", "2.2.14", "2.2.3", "2.2b1", "3.0rc1", "3.1b1", "3.2b1", "1.2.7", "1.5.2", "1.6.5", "1.1.2", "1.4.18", "1.5.10", "1.7.3", "1.7.4", "1.11.20", "1.4.9", "1.5.12", "1.11.29", "1.3.5", "1.4.15", "1.11.21", "1.11.28", "1.11a1", "1.4.1", "1.5.9", "1.7", "1.9.2", "2.0.12", "1.8.12", "2.2.10", "2.2.19", "2.2.6", "3.0.13", "3.0b1", "1.8.4", "2.0.13", "2.2rc1", "1.1.1", "1.11.10", "1.11.11", "1.3.3", "1.4.21", "1.6.2", "1.11.6", "1.2.1", "1.3.1", "1.4.2", "1.5", "1.7.5", "2.1.9", "1.8.19", "1.9.10", "2.0.8", "2.0.9", "2.1", "2.2.20", "2.2.13", "2.2.7", "2.2a1", "3.0.2", "1.8.14", "2.0rc1", "2.1b1", "3.0a1", "1.9.6", "2.0.10", "2.2.4", "2.2.21", "3.2.1", "3.1.9", "2.2.22", "3.2.2", "3.1.10", "3.1.11", "2.2.23", "3.2.3", "2.2.24", "3.1.12", "3.2.4", "3.2.5", "3.1.13", "3.2.6", "3.2.7", "4.0a1", "3.2.8", "4.0b1", "3.2.9", "4.0rc1", "3.2.10", "2.2.25", "3.1.14", "4.0", "4.0.1", "3.2.11", "2.2.26", "3.2.12", "2.2.27", "4.0.2", "4.0.3", "4.0.4", "3.2.13", "2.2.28", "4.1a1", "4.0.5", "4.1b1", "3.2.14", "4.0.6", "4.1rc1", "3.2.15", "4.0.7", "4.1", "4.1.1", "3.2.16", "4.0.8", "4.1.2", "4.1.3", "4.1.4", "4.1.5", "4.2a1", "4.0.9", "3.2.17", "4.1.6", "4.0.10", "3.2.18", "4.1.7", "4.2b1", "4.2rc1", "4.2", "4.1.8", "4.1.9", "4.2.1", "3.2.19", "4.2.2", "4.2.3", "3.2.20", "4.1.10", "4.2.4", "3.2.21", "4.2.5", "4.1.11", "5.0a1", "4.1.12", "3.2.22", "4.2.6", "5.0b1", "3.2.23", "4.1.13", "4.2.7", "5.0rc1", "5.0", "4.2.8", "4.2.9", "5.0.1", "3.2.24", "4.2.10", "5.0.2", "4.2.11", "5.0.3", "3.2.25", "5.0.4", "5.0.5", "4.2.12", "4.2.13", "5.0.6", "5.1a1", "5.1b1", "4.2.14", "5.0.7", "5.1rc1", "5.0.8", "4.2.15", "5.1", "4.2.16", "5.1.1", "5.0.9", "5.1.2", "5.1.3", "5.0.10", "4.2.17", "5.1.4", "5.0.11", "5.1.5", "4.2.18", "5.2a1", "5.0.12", "5.1.6", "4.2.19", "5.2b1", "4.2.20", "5.1.7", "5.0.13", "5.2rc1", "5.1.8", "5.0.14", "5.2", "5.2.1", "4.2.21", "5.1.9", "4.2.22", "5.1.10", "5.2.2", "4.2.23", "5.1.11", "5.2.3", "5.2.4", "5.2.5", "5.1.12", "5.2.6", "4.2.24", "5.1.13", "5.2.7", "4.2.25", "5.1.14", "4.2.26", "5.2.8", "4.2.27", "5.1.15", "5.2.9", "5.2.10", "4.2.28", "5.2.11", "4.2.29", "5.2.12", "4.2.30", "5.2.13", "5.2.14"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
Published date: 2026-07-07T15:32:57Z
CVE: CVE-2026-53878
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. DomainNameValidator does not prohibit newlines in domain names (unless used via a form field, since CharField strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.
Affected versions: ["6.0", "6.0.1", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "6.0.6", "1.4.22", "1.4.7", "1.6.10", "1.9.11", "3.0.7", "1.11.1", "1.4", "1.6.3", "1.8.1", "1.8.15", "1.9rc2", "3.2", "1.0.3", "1.11.24", "1.4.16", "1.4.17", "1.7.11", "1.7.8", "1.7.9", "1.8.17", "1.10rc1", "1.11.14", "1.11.23", "1.2", "1.2.2", "1.3.4", "1.7.10", "1.8.16", "1.8.18", "1.8.6", "1.8a1", "1.8b1", "1.8c1", "2.1.14", "2.1.4", "1.11.27", "1.5.6", "1.6.4", "1.8.2", "1.9", "3.0.3", "1.2.4", "1.7.6", "1.7.7", "1.8.5", "1.8b2", "2.0.3", "2.1.8", "2.1a1", "3.0.6", "1.0.2", "1.1.3", "2.1.15", "3.0.10", "3.0.11", "3.2rc1", "3.1a1", "1.1.4", "1.10.1", "1.11.3", "1.5.3", "1.9b1", "2.1.13", "1.11.18", "1.4.8", "1.8", "2.2.18", "1.0.4", "1.11.22", "1.2.5", "1.4.10", "1.4.12", "1.6.1", "1.8.10", "1.8.13", "2.0", "2.0.1", "2.0.4", "2.0a1", "1.10b1", "1.9.8", "2.2.17", "3.0.9", "1.2.6", "1.3", "1.5.1", "1.5.7", "1.6.11", "1.9.1", "2.2.9", "3.1.7", "1.11.12", "1.11.8", "1.11.9", "1.11rc1", "1.3.7", "1.7.2", "1.8.9", "1.9.9", "2.1.1", "3.1.6", "1.0.1", "1.10", "1.11.26", "1.5.5", "1.6.6", "2.1.3", "2.2.12", "3.0.1", "3.0.14", "3.0.8", "1.11.15", "2.0.5", "2.1.2", "3.0.4", "3.1rc1", "1.4.19", "1.6", "3.1.8", "1.10.8", "1.11.2", "1.4.11", "1.7.1", "1.10.4", "1.4.14", "1.4.20", "1.10.5", "1.10a1", "1.11", "1.11.25", "1.11.4", "1.11.5", "1.4.13", "1.4.3", "1.6.8", "1.10.6", "1.4.5", "1.6.7", "1.8.11", "1.11.7", "1.3.6", "1.11.13", "1.2.3", "1.3.2", "1.4.4", "1.5.8", "1.9.3", "1.9.4", "2.2.15", "3.0", "3.1.2", "3.1.4", "1.8.8", "1.9.12", "2.1.5", "2.2.16", "2.2.8", "3.1.5", "3.2a1", "1.10.2", "1.11.16", "1.11.17", "1.5.4", "1.6.9", "1.1", "1.10.3", "1.10.7", "1.11b1", "1.4.6", "1.5.11", "1.9.13", "2.0.7", "2.2.11", "2.2.2", "3.0.5", "3.1", "1.8.7", "1.9.5", "1.9rc1", "2.0b1", "2.0.6", "2.1.7", "3.0.12", "1.8.3", "1.9a1", "2.1.12", "2.1rc1", "2.2.5", "2.0.2", "2.1.10", "2.2", "3.1.1", "3.1.3", "1.9.7", "2.1.11", "2.2.1", "2.2.14", "2.2.3", "2.2b1", "3.0rc1", "3.1b1", "3.2b1", "1.2.7", "1.5.2", "1.6.5", "1.1.2", "1.4.18", "1.5.10", "1.7.3", "1.7.4", "1.11.20", "1.4.9", "1.5.12", "1.11.29", "1.3.5", "1.4.15", "1.11.21", "1.11.28", "1.11a1", "1.4.1", "1.5.9", "1.7", "1.9.2", "2.0.12", "1.8.12", "2.2.10", "2.2.19", "2.2.6", "3.0.13", "3.0b1", "1.8.4", "2.0.13", "2.2rc1", "1.1.1", "1.11.10", "1.11.11", "1.3.3", "1.4.21", "1.6.2", "1.11.6", "1.2.1", "1.3.1", "1.4.2", "1.5", "1.7.5", "2.1.9", "1.8.19", "1.9.10", "2.0.8", "2.0.9", "2.1", "2.2.20", "2.2.13", "2.2.7", "2.2a1", "3.0.2", "1.8.14", "2.0rc1", "2.1b1", "3.0a1", "1.9.6", "2.0.10", "2.2.4", "2.2.21", "3.2.1", "3.1.9", "2.2.22", "3.2.2", "3.1.10", "3.1.11", "2.2.23", "3.2.3", "2.2.24", "3.1.12", "3.2.4", "3.2.5", "3.1.13", "3.2.6", "3.2.7", "4.0a1", "3.2.8", "4.0b1", "3.2.9", "4.0rc1", "3.2.10", "2.2.25", "3.1.14", "4.0", "4.0.1", "3.2.11", "2.2.26", "3.2.12", "2.2.27", "4.0.2", "4.0.3", "4.0.4", "3.2.13", "2.2.28", "4.1a1", "4.0.5", "4.1b1", "3.2.14", "4.0.6", "4.1rc1", "3.2.15", "4.0.7", "4.1", "4.1.1", "3.2.16", "4.0.8", "4.1.2", "4.1.3", "4.1.4", "4.1.5", "4.2a1", "4.0.9", "3.2.17", "4.1.6", "4.0.10", "3.2.18", "4.1.7", "4.2b1", "4.2rc1", "4.2", "4.1.8", "4.1.9", "4.2.1", "3.2.19", "4.2.2", "4.2.3", "3.2.20", "4.1.10", "4.2.4", "3.2.21", "4.2.5", "4.1.11", "5.0a1", "4.1.12", "3.2.22", "4.2.6", "5.0b1", "3.2.23", "4.1.13", "4.2.7", "5.0rc1", "5.0", "4.2.8", "4.2.9", "5.0.1", "3.2.24", "4.2.10", "5.0.2", "4.2.11", "5.0.3", "3.2.25", "5.0.4", "5.0.5", "4.2.12", "4.2.13", "5.0.6", "5.1a1", "5.1b1", "4.2.14", "5.0.7", "5.1rc1", "5.0.8", "4.2.15", "5.1", "4.2.16", "5.1.1", "5.0.9", "5.1.2", "5.1.3", "5.0.10", "4.2.17", "5.1.4", "5.0.11", "5.1.5", "4.2.18", "5.2a1", "5.0.12", "5.1.6", "4.2.19", "5.2b1", "4.2.20", "5.1.7", "5.0.13", "5.2rc1", "5.1.8", "5.0.14", "5.2", "5.2.1", "4.2.21", "5.1.9", "4.2.22", "5.1.10", "5.2.2", "4.2.23", "5.1.11", "5.2.3", "5.2.4", "5.2.5", "5.1.12", "5.2.6", "4.2.24", "5.1.13", "5.2.7", "4.2.25", "5.1.14", "4.2.26", "5.2.8", "4.2.27", "5.1.15", "5.2.9", "5.2.10", "4.2.28", "5.2.11", "4.2.29", "5.2.12", "4.2.30", "5.2.13", "5.2.14", "5.2.15"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
Published date: 2026-06-03T15:30:43Z
CVE: CVE-2026-48587
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. django.utils.cache.has_vary_header() in Django does not strip leading or trailing whitespace from Vary response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Navid Rezazadeh for reporting this issue.
Affected versions: ["6.0", "6.0.1", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "1.4.22", "1.4.7", "1.6.10", "1.9.11", "3.0.7", "1.11.1", "1.4", "1.6.3", "1.8.1", "1.8.15", "1.9rc2", "3.2", "1.0.3", "1.11.24", "1.4.16", "1.4.17", "1.7.11", "1.7.8", "1.7.9", "1.8.17", "1.10rc1", "1.11.14", "1.11.23", "1.2", "1.2.2", "1.3.4", "1.7.10", "1.8.16", "1.8.18", "1.8.6", "1.8a1", "1.8b1", "1.8c1", "2.1.14", "2.1.4", "1.11.27", "1.5.6", "1.6.4", "1.8.2", "1.9", "3.0.3", "1.2.4", "1.7.6", "1.7.7", "1.8.5", "1.8b2", "2.0.3", "2.1.8", "2.1a1", "3.0.6", "1.0.2", "1.1.3", "2.1.15", "3.0.10", "3.0.11", "3.2rc1", "3.1a1", "1.1.4", "1.10.1", "1.11.3", "1.5.3", "1.9b1", "2.1.13", "1.11.18", "1.4.8", "1.8", "2.2.18", "1.0.4", "1.11.22", "1.2.5", "1.4.10", "1.4.12", "1.6.1", "1.8.10", "1.8.13", "2.0", "2.0.1", "2.0.4", "2.0a1", "1.10b1", "1.9.8", "2.2.17", "3.0.9", "1.2.6", "1.3", "1.5.1", "1.5.7", "1.6.11", "1.9.1", "2.2.9", "3.1.7", "1.11.12", "1.11.8", "1.11.9", "1.11rc1", "1.3.7", "1.7.2", "1.8.9", "1.9.9", "2.1.1", "3.1.6", "1.0.1", "1.10", "1.11.26", "1.5.5", "1.6.6", "2.1.3", "2.2.12", "3.0.1", "3.0.14", "3.0.8", "1.11.15", "2.0.5", "2.1.2", "3.0.4", "3.1rc1", "1.4.19", "1.6", "3.1.8", "1.10.8", "1.11.2", "1.4.11", "1.7.1", "1.10.4", "1.4.14", "1.4.20", "1.10.5", "1.10a1", "1.11", "1.11.25", "1.11.4", "1.11.5", "1.4.13", "1.4.3", "1.6.8", "1.10.6", "1.4.5", "1.6.7", "1.8.11", "1.11.7", "1.3.6", "1.11.13", "1.2.3", "1.3.2", "1.4.4", "1.5.8", "1.9.3", "1.9.4", "2.2.15", "3.0", "3.1.2", "3.1.4", "1.8.8", "1.9.12", "2.1.5", "2.2.16", "2.2.8", "3.1.5", "3.2a1", "1.10.2", "1.11.16", "1.11.17", "1.5.4", "1.6.9", "1.1", "1.10.3", "1.10.7", "1.11b1", "1.4.6", "1.5.11", "1.9.13", "2.0.7", "2.2.11", "2.2.2", "3.0.5", "3.1", "1.8.7", "1.9.5", "1.9rc1", "2.0b1", "2.0.6", "2.1.7", "3.0.12", "1.8.3", "1.9a1", "2.1.12", "2.1rc1", "2.2.5", "2.0.2", "2.1.10", "2.2", "3.1.1", "3.1.3", "1.9.7", "2.1.11", "2.2.1", "2.2.14", "2.2.3", "2.2b1", "3.0rc1", "3.1b1", "3.2b1", "1.2.7", "1.5.2", "1.6.5", "1.1.2", "1.4.18", "1.5.10", "1.7.3", "1.7.4", "1.11.20", "1.4.9", "1.5.12", "1.11.29", "1.3.5", "1.4.15", "1.11.21", "1.11.28", "1.11a1", "1.4.1", "1.5.9", "1.7", "1.9.2", "2.0.12", "1.8.12", "2.2.10", "2.2.19", "2.2.6", "3.0.13", "3.0b1", "1.8.4", "2.0.13", "2.2rc1", "1.1.1", "1.11.10", "1.11.11", "1.3.3", "1.4.21", "1.6.2", "1.11.6", "1.2.1", "1.3.1", "1.4.2", "1.5", "1.7.5", "2.1.9", "1.8.19", "1.9.10", "2.0.8", "2.0.9", "2.1", "2.2.20", "2.2.13", "2.2.7", "2.2a1", "3.0.2", "1.8.14", "2.0rc1", "2.1b1", "3.0a1", "1.9.6", "2.0.10", "2.2.4", "2.2.21", "3.2.1", "3.1.9", "2.2.22", "3.2.2", "3.1.10", "3.1.11", "2.2.23", "3.2.3", "2.2.24", "3.1.12", "3.2.4", "3.2.5", "3.1.13", "3.2.6", "3.2.7", "4.0a1", "3.2.8", "4.0b1", "3.2.9", "4.0rc1", "3.2.10", "2.2.25", "3.1.14", "4.0", "4.0.1", "3.2.11", "2.2.26", "3.2.12", "2.2.27", "4.0.2", "4.0.3", "4.0.4", "3.2.13", "2.2.28", "4.1a1", "4.0.5", "4.1b1", "3.2.14", "4.0.6", "4.1rc1", "3.2.15", "4.0.7", "4.1", "4.1.1", "3.2.16", "4.0.8", "4.1.2", "4.1.3", "4.1.4", "4.1.5", "4.2a1", "4.0.9", "3.2.17", "4.1.6", "4.0.10", "3.2.18", "4.1.7", "4.2b1", "4.2rc1", "4.2", "4.1.8", "4.1.9", "4.2.1", "3.2.19", "4.2.2", "4.2.3", "3.2.20", "4.1.10", "4.2.4", "3.2.21", "4.2.5", "4.1.11", "5.0a1", "4.1.12", "3.2.22", "4.2.6", "5.0b1", "3.2.23", "4.1.13", "4.2.7", "5.0rc1", "5.0", "4.2.8", "4.2.9", "5.0.1", "3.2.24", "4.2.10", "5.0.2", "4.2.11", "5.0.3", "3.2.25", "5.0.4", "5.0.5", "4.2.12", "4.2.13", "5.0.6", "5.1a1", "5.1b1", "4.2.14", "5.0.7", "5.1rc1", "5.0.8", "4.2.15", "5.1", "4.2.16", "5.1.1", "5.0.9", "5.1.2", "5.1.3", "5.0.10", "4.2.17", "5.1.4", "5.0.11", "5.1.5", "4.2.18", "5.2a1", "5.0.12", "5.1.6", "4.2.19", "5.2b1", "4.2.20", "5.1.7", "5.0.13", "5.2rc1", "5.1.8", "5.0.14", "5.2", "5.2.1", "4.2.21", "5.1.9", "4.2.22", "5.1.10", "5.2.2", "4.2.23", "5.1.11", "5.2.3", "5.2.4", "5.2.5", "5.1.12", "5.2.6", "4.2.24", "5.1.13", "5.2.7", "4.2.25", "5.1.14", "4.2.26", "5.2.8", "4.2.27", "5.1.15", "5.2.9", "5.2.10", "4.2.28", "5.2.11", "4.2.29", "5.2.12", "4.2.30", "5.2.13", "5.2.14"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
Published date: 2026-07-07T15:32:57Z
CVE: CVE-2026-53877
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. django.contrib.gis.gdal.GDALRaster over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the vsi_buffer property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.
Affected versions: ["6.0", "6.0.1", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "6.0.6", "1.4.22", "1.4.7", "1.6.10", "1.9.11", "3.0.7", "1.11.1", "1.4", "1.6.3", "1.8.1", "1.8.15", "1.9rc2", "3.2", "1.0.3", "1.11.24", "1.4.16", "1.4.17", "1.7.11", "1.7.8", "1.7.9", "1.8.17", "1.10rc1", "1.11.14", "1.11.23", "1.2", "1.2.2", "1.3.4", "1.7.10", "1.8.16", "1.8.18", "1.8.6", "1.8a1", "1.8b1", "1.8c1", "2.1.14", "2.1.4", "1.11.27", "1.5.6", "1.6.4", "1.8.2", "1.9", "3.0.3", "1.2.4", "1.7.6", "1.7.7", "1.8.5", "1.8b2", "2.0.3", "2.1.8", "2.1a1", "3.0.6", "1.0.2", "1.1.3", "2.1.15", "3.0.10", "3.0.11", "3.2rc1", "3.1a1", "1.1.4", "1.10.1", "1.11.3", "1.5.3", "1.9b1", "2.1.13", "1.11.18", "1.4.8", "1.8", "2.2.18", "1.0.4", "1.11.22", "1.2.5", "1.4.10", "1.4.12", "1.6.1", "1.8.10", "1.8.13", "2.0", "2.0.1", "2.0.4", "2.0a1", "1.10b1", "1.9.8", "2.2.17", "3.0.9", "1.2.6", "1.3", "1.5.1", "1.5.7", "1.6.11", "1.9.1", "2.2.9", "3.1.7", "1.11.12", "1.11.8", "1.11.9", "1.11rc1", "1.3.7", "1.7.2", "1.8.9", "1.9.9", "2.1.1", "3.1.6", "1.0.1", "1.10", "1.11.26", "1.5.5", "1.6.6", "2.1.3", "2.2.12", "3.0.1", "3.0.14", "3.0.8", "1.11.15", "2.0.5", "2.1.2", "3.0.4", "3.1rc1", "1.4.19", "1.6", "3.1.8", "1.10.8", "1.11.2", "1.4.11", "1.7.1", "1.10.4", "1.4.14", "1.4.20", "1.10.5", "1.10a1", "1.11", "1.11.25", "1.11.4", "1.11.5", "1.4.13", "1.4.3", "1.6.8", "1.10.6", "1.4.5", "1.6.7", "1.8.11", "1.11.7", "1.3.6", "1.11.13", "1.2.3", "1.3.2", "1.4.4", "1.5.8", "1.9.3", "1.9.4", "2.2.15", "3.0", "3.1.2", "3.1.4", "1.8.8", "1.9.12", "2.1.5", "2.2.16", "2.2.8", "3.1.5", "3.2a1", "1.10.2", "1.11.16", "1.11.17", "1.5.4", "1.6.9", "1.1", "1.10.3", "1.10.7", "1.11b1", "1.4.6", "1.5.11", "1.9.13", "2.0.7", "2.2.11", "2.2.2", "3.0.5", "3.1", "1.8.7", "1.9.5", "1.9rc1", "2.0b1", "2.0.6", "2.1.7", "3.0.12", "1.8.3", "1.9a1", "2.1.12", "2.1rc1", "2.2.5", "2.0.2", "2.1.10", "2.2", "3.1.1", "3.1.3", "1.9.7", "2.1.11", "2.2.1", "2.2.14", "2.2.3", "2.2b1", "3.0rc1", "3.1b1", "3.2b1", "1.2.7", "1.5.2", "1.6.5", "1.1.2", "1.4.18", "1.5.10", "1.7.3", "1.7.4", "1.11.20", "1.4.9", "1.5.12", "1.11.29", "1.3.5", "1.4.15", "1.11.21", "1.11.28", "1.11a1", "1.4.1", "1.5.9", "1.7", "1.9.2", "2.0.12", "1.8.12", "2.2.10", "2.2.19", "2.2.6", "3.0.13", "3.0b1", "1.8.4", "2.0.13", "2.2rc1", "1.1.1", "1.11.10", "1.11.11", "1.3.3", "1.4.21", "1.6.2", "1.11.6", "1.2.1", "1.3.1", "1.4.2", "1.5", "1.7.5", "2.1.9", "1.8.19", "1.9.10", "2.0.8", "2.0.9", "2.1", "2.2.20", "2.2.13", "2.2.7", "2.2a1", "3.0.2", "1.8.14", "2.0rc1", "2.1b1", "3.0a1", "1.9.6", "2.0.10", "2.2.4", "2.2.21", "3.2.1", "3.1.9", "2.2.22", "3.2.2", "3.1.10", "3.1.11", "2.2.23", "3.2.3", "2.2.24", "3.1.12", "3.2.4", "3.2.5", "3.1.13", "3.2.6", "3.2.7", "4.0a1", "3.2.8", "4.0b1", "3.2.9", "4.0rc1", "3.2.10", "2.2.25", "3.1.14", "4.0", "4.0.1", "3.2.11", "2.2.26", "3.2.12", "2.2.27", "4.0.2", "4.0.3", "4.0.4", "3.2.13", "2.2.28", "4.1a1", "4.0.5", "4.1b1", "3.2.14", "4.0.6", "4.1rc1", "3.2.15", "4.0.7", "4.1", "4.1.1", "3.2.16", "4.0.8", "4.1.2", "4.1.3", "4.1.4", "4.1.5", "4.2a1", "4.0.9", "3.2.17", "4.1.6", "4.0.10", "3.2.18", "4.1.7", "4.2b1", "4.2rc1", "4.2", "4.1.8", "4.1.9", "4.2.1", "3.2.19", "4.2.2", "4.2.3", "3.2.20", "4.1.10", "4.2.4", "3.2.21", "4.2.5", "4.1.11", "5.0a1", "4.1.12", "3.2.22", "4.2.6", "5.0b1", "3.2.23", "4.1.13", "4.2.7", "5.0rc1", "5.0", "4.2.8", "4.2.9", "5.0.1", "3.2.24", "4.2.10", "5.0.2", "4.2.11", "5.0.3", "3.2.25", "5.0.4", "5.0.5", "4.2.12", "4.2.13", "5.0.6", "5.1a1", "5.1b1", "4.2.14", "5.0.7", "5.1rc1", "5.0.8", "4.2.15", "5.1", "4.2.16", "5.1.1", "5.0.9", "5.1.2", "5.1.3", "5.0.10", "4.2.17", "5.1.4", "5.0.11", "5.1.5", "4.2.18", "5.2a1", "5.0.12", "5.1.6", "4.2.19", "5.2b1", "4.2.20", "5.1.7", "5.0.13", "5.2rc1", "5.1.8", "5.0.14", "5.2", "5.2.1", "4.2.21", "5.1.9", "4.2.22", "5.1.10", "5.2.2", "4.2.23", "5.1.11", "5.2.3", "5.2.4", "5.2.5", "5.1.12", "5.2.6", "4.2.24", "5.1.13", "5.2.7", "4.2.25", "5.1.14", "4.2.26", "5.2.8", "4.2.27", "5.1.15", "5.2.9", "5.2.10", "4.2.28", "5.2.11", "4.2.29", "5.2.12", "4.2.30", "5.2.13", "5.2.14", "5.2.15"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
Published date: 2025-11-05T15:31:07Z
CVE: CVE-2025-64459
An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods QuerySet.filter(), QuerySet.exclude(), and QuerySet.get(), and the class Q(), are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the _connector argument. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank cyberstan for reporting this issue.
Affected versions: ["1.4.22", "1.4.7", "1.6.10", "1.9.11", "3.0.7", "1.11.1", "1.4", "1.6.3", "1.8.1", "1.8.15", "1.9rc2", "3.2", "1.0.3", "1.11.24", "1.4.16", "1.4.17", "1.7.11", "1.7.8", "1.7.9", "1.8.17", "1.10rc1", "1.11.14", "1.11.23", "1.2", "1.2.2", "1.3.4", "1.7.10", "1.8.16", "1.8.18", "1.8.6", "1.8a1", "1.8b1", "1.8c1", "2.1.14", "2.1.4", "1.11.27", "1.5.6", "1.6.4", "1.8.2", "1.9", "3.0.3", "1.2.4", "1.7.6", "1.7.7", "1.8.5", "1.8b2", "2.0.3", "2.1.8", "2.1a1", "3.0.6", "1.0.2", "1.1.3", "2.1.15", "3.0.10", "3.0.11", "3.2rc1", "3.1a1", "1.1.4", "1.10.1", "1.11.3", "1.5.3", "1.9b1", "2.1.13", "1.11.18", "1.4.8", "1.8", "2.2.18", "1.0.4", "1.11.22", "1.2.5", "1.4.10", "1.4.12", "1.6.1", "1.8.10", "1.8.13", "2.0", "2.0.1", "2.0.4", "2.0a1", "1.10b1", "1.9.8", "2.2.17", "3.0.9", "1.2.6", "1.3", "1.5.1", "1.5.7", "1.6.11", "1.9.1", "2.2.9", "3.1.7", "1.11.12", "1.11.8", "1.11.9", "1.11rc1", "1.3.7", "1.7.2", "1.8.9", "1.9.9", "2.1.1", "3.1.6", "1.0.1", "1.10", "1.11.26", "1.5.5", "1.6.6", "2.1.3", "2.2.12", "3.0.1", "3.0.14", "3.0.8", "1.11.15", "2.0.5", "2.1.2", "3.0.4", "3.1rc1", "1.4.19", "1.6", "3.1.8", "1.10.8", "1.11.2", "1.4.11", "1.7.1", "1.10.4", "1.4.14", "1.4.20", "1.10.5", "1.10a1", "1.11", "1.11.25", "1.11.4", "1.11.5", "1.4.13", "1.4.3", "1.6.8", "1.10.6", "1.4.5", "1.6.7", "1.8.11", "1.11.7", "1.3.6", "1.11.13", "1.2.3", "1.3.2", "1.4.4", "1.5.8", "1.9.3", "1.9.4", "2.2.15", "3.0", "3.1.2", "3.1.4", "1.8.8", "1.9.12", "2.1.5", "2.2.16", "2.2.8", "3.1.5", "3.2a1", "1.10.2", "1.11.16", "1.11.17", "1.5.4", "1.6.9", "1.1", "1.10.3", "1.10.7", "1.11b1", "1.4.6", "1.5.11", "1.9.13", "2.0.7", "2.2.11", "2.2.2", "3.0.5", "3.1", "1.8.7", "1.9.5", "1.9rc1", "2.0b1", "2.0.6", "2.1.7", "3.0.12", "1.8.3", "1.9a1", "2.1.12", "2.1rc1", "2.2.5", "2.0.2", "2.1.10", "2.2", "3.1.1", "3.1.3", "1.9.7", "2.1.11", "2.2.1", "2.2.14", "2.2.3", "2.2b1", "3.0rc1", "3.1b1", "3.2b1", "1.2.7", "1.5.2", "1.6.5", "1.1.2", "1.4.18", "1.5.10", "1.7.3", "1.7.4", "1.11.20", "1.4.9", "1.5.12", "1.11.29", "1.3.5", "1.4.15", "1.11.21", "1.11.28", "1.11a1", "1.4.1", "1.5.9", "1.7", "1.9.2", "2.0.12", "1.8.12", "2.2.10", "2.2.19", "2.2.6", "3.0.13", "3.0b1", "1.8.4", "2.0.13", "2.2rc1", "1.1.1", "1.11.10", "1.11.11", "1.3.3", "1.4.21", "1.6.2", "1.11.6", "1.2.1", "1.3.1", "1.4.2", "1.5", "1.7.5", "2.1.9", "1.8.19", "1.9.10", "2.0.8", "2.0.9", "2.1", "2.2.20", "2.2.13", "2.2.7", "2.2a1", "3.0.2", "1.8.14", "2.0rc1", "2.1b1", "3.0a1", "1.9.6", "2.0.10", "2.2.4", "2.2.21", "3.2.1", "3.1.9", "2.2.22", "3.2.2", "3.1.10", "3.1.11", "2.2.23", "3.2.3", "2.2.24", "3.1.12", "3.2.4", "3.2.5", "3.1.13", "3.2.6", "3.2.7", "4.0a1", "3.2.8", "4.0b1", "3.2.9", "4.0rc1", "3.2.10", "2.2.25", "3.1.14", "4.0", "4.0.1", "3.2.11", "2.2.26", "3.2.12", "2.2.27", "4.0.2", "4.0.3", "4.0.4", "3.2.13", "2.2.28", "4.1a1", "4.0.5", "4.1b1", "3.2.14", "4.0.6", "4.1rc1", "3.2.15", "4.0.7", "4.1", "4.1.1", "3.2.16", "4.0.8", "4.1.2", "4.1.3", "4.1.4", "4.1.5", "4.2a1", "4.0.9", "3.2.17", "4.1.6", "4.0.10", "3.2.18", "4.1.7", "4.2b1", "4.2rc1", "4.2", "4.1.8", "4.1.9", "4.2.1", "3.2.19", "4.2.2", "4.2.3", "3.2.20", "4.1.10", "4.2.4", "3.2.21", "4.2.5", "4.1.11", "4.1.12", "3.2.22", "4.2.6", "3.2.23", "4.1.13", "4.2.7", "4.2.8", "4.2.9", "3.2.24", "4.2.10", "4.2.11", "3.2.25", "4.2.12", "4.2.13", "4.2.14", "4.2.15", "4.2.16", "4.2.17", "4.2.18", "4.2.19", "4.2.20", "4.2.21", "4.2.22", "4.2.23", "4.2.24", "4.2.25", "5.0a1", "5.0b1", "5.0rc1", "5.0", "5.0.1", "5.0.2", "5.0.3", "5.0.4", "5.0.5", "5.0.6", "5.1a1", "5.1b1", "5.0.7", "5.1rc1", "5.0.8", "5.1", "5.1.1", "5.0.9", "5.1.2", "5.1.3", "5.0.10", "5.1.4", "5.0.11", "5.1.5", "5.0.12", "5.1.6", "5.1.7", "5.0.13", "5.1.8", "5.0.14", "5.1.9", "5.1.10", "5.1.11", "5.1.12", "5.1.13", "5.2a1", "5.2b1", "5.2rc1", "5.2", "5.2.1", "5.2.2", "5.2.3", "5.2.4", "5.2.5", "5.2.6", "5.2.7"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
Published date: 2019-01-04T17:50:17Z
CVE: CVE-2017-7234
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the django.views.static.serve() view could redirect to any other domain, aka an open redirect vulnerability.
Affected versions: ["1.8.1", "1.8.15", "1.8.17", "1.8.16", "1.8.6", "1.8.2", "1.8.5", "1.8", "1.8.10", "1.8.13", "1.8.9", "1.8.11", "1.8.8", "1.8.7", "1.8.3", "1.8.12", "1.8.4", "1.8.14", "1.9.11", "1.9", "1.9.8", "1.9.1", "1.9.9", "1.9.3", "1.9.4", "1.9.12", "1.9.5", "1.9.7", "1.9.2", "1.9.10", "1.9.6", "1.10.1", "1.10", "1.10.4", "1.10.5", "1.10.6", "1.10.2", "1.10.3"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
Published date: 2026-06-03T15:30:43Z
CVE: CVE-2026-6873
An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. django.http.HttpRequest.get_signed_cookie in Django uses a non-injective salt derivation (concatenating the cookie name and salt argument), which allows a remote attacker to use a cookie in a context different from the one where it was signed, via distinct (name, salt) pairs that produce the same concatenation. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Peng Zhou for reporting this issue.
Affected versions: ["6.0", "6.0.1", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "1.4.22", "1.4.7", "1.6.10", "1.9.11", "3.0.7", "1.11.1", "1.4", "1.6.3", "1.8.1", "1.8.15", "1.9rc2", "3.2", "1.0.3", "1.11.24", "1.4.16", "1.4.17", "1.7.11", "1.7.8", "1.7.9", "1.8.17", "1.10rc1", "1.11.14", "1.11.23", "1.2", "1.2.2", "1.3.4", "1.7.10", "1.8.16", "1.8.18", "1.8.6", "1.8a1", "1.8b1", "1.8c1", "2.1.14", "2.1.4", "1.11.27", "1.5.6", "1.6.4", "1.8.2", "1.9", "3.0.3", "1.2.4", "1.7.6", "1.7.7", "1.8.5", "1.8b2", "2.0.3", "2.1.8", "2.1a1", "3.0.6", "1.0.2", "1.1.3", "2.1.15", "3.0.10", "3.0.11", "3.2rc1", "3.1a1", "1.1.4", "1.10.1", "1.11.3", "1.5.3", "1.9b1", "2.1.13", "1.11.18", "1.4.8", "1.8", "2.2.18", "1.0.4", "1.11.22", "1.2.5", "1.4.10", "1.4.12", "1.6.1", "1.8.10", "1.8.13", "2.0", "2.0.1", "2.0.4", "2.0a1", "1.10b1", "1.9.8", "2.2.17", "3.0.9", "1.2.6", "1.3", "1.5.1", "1.5.7", "1.6.11", "1.9.1", "2.2.9", "3.1.7", "1.11.12", "1.11.8", "1.11.9", "1.11rc1", "1.3.7", "1.7.2", "1.8.9", "1.9.9", "2.1.1", "3.1.6", "1.0.1", "1.10", "1.11.26", "1.5.5", "1.6.6", "2.1.3", "2.2.12", "3.0.1", "3.0.14", "3.0.8", "1.11.15", "2.0.5", "2.1.2", "3.0.4", "3.1rc1", "1.4.19", "1.6", "3.1.8", "1.10.8", "1.11.2", "1.4.11", "1.7.1", "1.10.4", "1.4.14", "1.4.20", "1.10.5", "1.10a1", "1.11", "1.11.25", "1.11.4", "1.11.5", "1.4.13", "1.4.3", "1.6.8", "1.10.6", "1.4.5", "1.6.7", "1.8.11", "1.11.7", "1.3.6", "1.11.13", "1.2.3", "1.3.2", "1.4.4", "1.5.8", "1.9.3", "1.9.4", "2.2.15", "3.0", "3.1.2", "3.1.4", "1.8.8", "1.9.12", "2.1.5", "2.2.16", "2.2.8", "3.1.5", "3.2a1", "1.10.2", "1.11.16", "1.11.17", "1.5.4", "1.6.9", "1.1", "1.10.3", "1.10.7", "1.11b1", "1.4.6", "1.5.11", "1.9.13", "2.0.7", "2.2.11", "2.2.2", "3.0.5", "3.1", "1.8.7", "1.9.5", "1.9rc1", "2.0b1", "2.0.6", "2.1.7", "3.0.12", "1.8.3", "1.9a1", "2.1.12", "2.1rc1", "2.2.5", "2.0.2", "2.1.10", "2.2", "3.1.1", "3.1.3", "1.9.7", "2.1.11", "2.2.1", "2.2.14", "2.2.3", "2.2b1", "3.0rc1", "3.1b1", "3.2b1", "1.2.7", "1.5.2", "1.6.5", "1.1.2", "1.4.18", "1.5.10", "1.7.3", "1.7.4", "1.11.20", "1.4.9", "1.5.12", "1.11.29", "1.3.5", "1.4.15", "1.11.21", "1.11.28", "1.11a1", "1.4.1", "1.5.9", "1.7", "1.9.2", "2.0.12", "1.8.12", "2.2.10", "2.2.19", "2.2.6", "3.0.13", "3.0b1", "1.8.4", "2.0.13", "2.2rc1", "1.1.1", "1.11.10", "1.11.11", "1.3.3", "1.4.21", "1.6.2", "1.11.6", "1.2.1", "1.3.1", "1.4.2", "1.5", "1.7.5", "2.1.9", "1.8.19", "1.9.10", "2.0.8", "2.0.9", "2.1", "2.2.20", "2.2.13", "2.2.7", "2.2a1", "3.0.2", "1.8.14", "2.0rc1", "2.1b1", "3.0a1", "1.9.6", "2.0.10", "2.2.4", "2.2.21", "3.2.1", "3.1.9", "2.2.22", "3.2.2", "3.1.10", "3.1.11", "2.2.23", "3.2.3", "2.2.24", "3.1.12", "3.2.4", "3.2.5", "3.1.13", "3.2.6", "3.2.7", "4.0a1", "3.2.8", "4.0b1", "3.2.9", "4.0rc1", "3.2.10", "2.2.25", "3.1.14", "4.0", "4.0.1", "3.2.11", "2.2.26", "3.2.12", "2.2.27", "4.0.2", "4.0.3", "4.0.4", "3.2.13", "2.2.28", "4.1a1", "4.0.5", "4.1b1", "3.2.14", "4.0.6", "4.1rc1", "3.2.15", "4.0.7", "4.1", "4.1.1", "3.2.16", "4.0.8", "4.1.2", "4.1.3", "4.1.4", "4.1.5", "4.2a1", "4.0.9", "3.2.17", "4.1.6", "4.0.10", "3.2.18", "4.1.7", "4.2b1", "4.2rc1", "4.2", "4.1.8", "4.1.9", "4.2.1", "3.2.19", "4.2.2", "4.2.3", "3.2.20", "4.1.10", "4.2.4", "3.2.21", "4.2.5", "4.1.11", "5.0a1", "4.1.12", "3.2.22", "4.2.6", "5.0b1", "3.2.23", "4.1.13", "4.2.7", "5.0rc1", "5.0", "4.2.8", "4.2.9", "5.0.1", "3.2.24", "4.2.10", "5.0.2", "4.2.11", "5.0.3", "3.2.25", "5.0.4", "5.0.5", "4.2.12", "4.2.13", "5.0.6", "5.1a1", "5.1b1", "4.2.14", "5.0.7", "5.1rc1", "5.0.8", "4.2.15", "5.1", "4.2.16", "5.1.1", "5.0.9", "5.1.2", "5.1.3", "5.0.10", "4.2.17", "5.1.4", "5.0.11", "5.1.5", "4.2.18", "5.2a1", "5.0.12", "5.1.6", "4.2.19", "5.2b1", "4.2.20", "5.1.7", "5.0.13", "5.2rc1", "5.1.8", "5.0.14", "5.2", "5.2.1", "4.2.21", "5.1.9", "4.2.22", "5.1.10", "5.2.2", "4.2.23", "5.1.11", "5.2.3", "5.2.4", "5.2.5", "5.1.12", "5.2.6", "4.2.24", "5.1.13", "5.2.7", "4.2.25", "5.1.14", "4.2.26", "5.2.8", "4.2.27", "5.1.15", "5.2.9", "5.2.10", "4.2.28", "5.2.11", "4.2.29", "5.2.12", "4.2.30", "5.2.13", "5.2.14"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
Published date: 2020-02-11T21:03:20Z
CVE: CVE-2020-7471
Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with a user-specified column delimiter). By passing a suitably crafted delimiter to a contrib.postgres.aggregates.StringAgg instance, it was possible to break escaping and inject malicious SQL.
Affected versions: ["1.4.22", "1.4.7", "1.6.10", "1.9.11", "1.11.1", "1.4", "1.6.3", "1.8.1", "1.8.15", "1.0.3", "1.11.24", "1.4.16", "1.4.17", "1.7.11", "1.7.8", "1.7.9", "1.8.17", "1.10rc1", "1.11.14", "1.11.23", "1.2", "1.2.2", "1.3.4", "1.7.10", "1.8.16", "1.8.18", "1.8.6", "1.11.27", "1.5.6", "1.6.4", "1.8.2", "1.9", "1.2.4", "1.7.6", "1.7.7", "1.8.5", "1.0.2", "1.1.3", "1.1.4", "1.10.1", "1.11.3", "1.5.3", "1.11.18", "1.4.8", "1.8", "1.0.4", "1.11.22", "1.2.5", "1.4.10", "1.4.12", "1.6.1", "1.8.10", "1.8.13", "1.10b1", "1.9.8", "1.2.6", "1.3", "1.5.1", "1.5.7", "1.6.11", "1.9.1", "1.11.12", "1.11.8", "1.11.9", "1.11rc1", "1.3.7", "1.7.2", "1.8.9", "1.9.9", "1.0.1", "1.10", "1.11.26", "1.5.5", "1.6.6", "1.11.15", "1.4.19", "1.6", "1.10.8", "1.11.2", "1.4.11", "1.7.1", "1.10.4", "1.4.14", "1.4.20", "1.10.5", "1.10a1", "1.11", "1.11.25", "1.11.4", "1.11.5", "1.4.13", "1.4.3", "1.6.8", "1.10.6", "1.4.5", "1.6.7", "1.8.11", "1.11.7", "1.3.6", "1.11.13", "1.2.3", "1.3.2", "1.4.4", "1.5.8", "1.9.3", "1.9.4", "1.8.8", "1.9.12", "1.10.2", "1.11.16", "1.11.17", "1.5.4", "1.6.9", "1.1", "1.10.3", "1.10.7", "1.11b1", "1.4.6", "1.5.11", "1.9.13", "1.8.7", "1.9.5", "1.8.3", "1.9.7", "1.2.7", "1.5.2", "1.6.5", "1.1.2", "1.4.18", "1.5.10", "1.7.3", "1.7.4", "1.11.20", "1.4.9", "1.5.12", "1.3.5", "1.4.15", "1.11.21", "1.11a1", "1.4.1", "1.5.9", "1.7", "1.9.2", "1.8.12", "1.8.4", "1.1.1", "1.11.10", "1.11.11", "1.3.3", "1.4.21", "1.6.2", "1.11.6", "1.2.1", "1.3.1", "1.4.2", "1.5", "1.7.5", "1.8.19", "1.9.10", "1.8.14", "1.9.6"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
Published date: 2025-11-05T15:31:07Z
CVE: CVE-2025-64458
An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is slow on Windows. As a consequence, django.http.HttpResponseRedirect, django.http.HttpResponsePermanentRedirect, and the shortcut django.shortcuts.redirect were subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.
Affected versions: ["1.4.22", "1.4.7", "1.6.10", "1.9.11", "3.0.7", "1.11.1", "1.4", "1.6.3", "1.8.1", "1.8.15", "1.9rc2", "3.2", "1.0.3", "1.11.24", "1.4.16", "1.4.17", "1.7.11", "1.7.8", "1.7.9", "1.8.17", "1.10rc1", "1.11.14", "1.11.23", "1.2", "1.2.2", "1.3.4", "1.7.10", "1.8.16", "1.8.18", "1.8.6", "1.8a1", "1.8b1", "1.8c1", "2.1.14", "2.1.4", "1.11.27", "1.5.6", "1.6.4", "1.8.2", "1.9", "3.0.3", "1.2.4", "1.7.6", "1.7.7", "1.8.5", "1.8b2", "2.0.3", "2.1.8", "2.1a1", "3.0.6", "1.0.2", "1.1.3", "2.1.15", "3.0.10", "3.0.11", "3.2rc1", "3.1a1", "1.1.4", "1.10.1", "1.11.3", "1.5.3", "1.9b1", "2.1.13", "1.11.18", "1.4.8", "1.8", "2.2.18", "1.0.4", "1.11.22", "1.2.5", "1.4.10", "1.4.12", "1.6.1", "1.8.10", "1.8.13", "2.0", "2.0.1", "2.0.4", "2.0a1", "1.10b1", "1.9.8", "2.2.17", "3.0.9", "1.2.6", "1.3", "1.5.1", "1.5.7", "1.6.11", "1.9.1", "2.2.9", "3.1.7", "1.11.12", "1.11.8", "1.11.9", "1.11rc1", "1.3.7", "1.7.2", "1.8.9", "1.9.9", "2.1.1", "3.1.6", "1.0.1", "1.10", "1.11.26", "1.5.5", "1.6.6", "2.1.3", "2.2.12", "3.0.1", "3.0.14", "3.0.8", "1.11.15", "2.0.5", "2.1.2", "3.0.4", "3.1rc1", "1.4.19", "1.6", "3.1.8", "1.10.8", "1.11.2", "1.4.11", "1.7.1", "1.10.4", "1.4.14", "1.4.20", "1.10.5", "1.10a1", "1.11", "1.11.25", "1.11.4", "1.11.5", "1.4.13", "1.4.3", "1.6.8", "1.10.6", "1.4.5", "1.6.7", "1.8.11", "1.11.7", "1.3.6", "1.11.13", "1.2.3", "1.3.2", "1.4.4", "1.5.8", "1.9.3", "1.9.4", "2.2.15", "3.0", "3.1.2", "3.1.4", "1.8.8", "1.9.12", "2.1.5", "2.2.16", "2.2.8", "3.1.5", "3.2a1", "1.10.2", "1.11.16", "1.11.17", "1.5.4", "1.6.9", "1.1", "1.10.3", "1.10.7", "1.11b1", "1.4.6", "1.5.11", "1.9.13", "2.0.7", "2.2.11", "2.2.2", "3.0.5", "3.1", "1.8.7", "1.9.5", "1.9rc1", "2.0b1", "2.0.6", "2.1.7", "3.0.12", "1.8.3", "1.9a1", "2.1.12", "2.1rc1", "2.2.5", "2.0.2", "2.1.10", "2.2", "3.1.1", "3.1.3", "1.9.7", "2.1.11", "2.2.1", "2.2.14", "2.2.3", "2.2b1", "3.0rc1", "3.1b1", "3.2b1", "1.2.7", "1.5.2", "1.6.5", "1.1.2", "1.4.18", "1.5.10", "1.7.3", "1.7.4", "1.11.20", "1.4.9", "1.5.12", "1.11.29", "1.3.5", "1.4.15", "1.11.21", "1.11.28", "1.11a1", "1.4.1", "1.5.9", "1.7", "1.9.2", "2.0.12", "1.8.12", "2.2.10", "2.2.19", "2.2.6", "3.0.13", "3.0b1", "1.8.4", "2.0.13", "2.2rc1", "1.1.1", "1.11.10", "1.11.11", "1.3.3", "1.4.21", "1.6.2", "1.11.6", "1.2.1", "1.3.1", "1.4.2", "1.5", "1.7.5", "2.1.9", "1.8.19", "1.9.10", "2.0.8", "2.0.9", "2.1", "2.2.20", "2.2.13", "2.2.7", "2.2a1", "3.0.2", "1.8.14", "2.0rc1", "2.1b1", "3.0a1", "1.9.6", "2.0.10", "2.2.4", "2.2.21", "3.2.1", "3.1.9", "2.2.22", "3.2.2", "3.1.10", "3.1.11", "2.2.23", "3.2.3", "2.2.24", "3.1.12", "3.2.4", "3.2.5", "3.1.13", "3.2.6", "3.2.7", "4.0a1", "3.2.8", "4.0b1", "3.2.9", "4.0rc1", "3.2.10", "2.2.25", "3.1.14", "4.0", "4.0.1", "3.2.11", "2.2.26", "3.2.12", "2.2.27", "4.0.2", "4.0.3", "4.0.4", "3.2.13", "2.2.28", "4.1a1", "4.0.5", "4.1b1", "3.2.14", "4.0.6", "4.1rc1", "3.2.15", "4.0.7", "4.1", "4.1.1", "3.2.16", "4.0.8", "4.1.2", "4.1.3", "4.1.4", "4.1.5", "4.2a1", "4.0.9", "3.2.17", "4.1.6", "4.0.10", "3.2.18", "4.1.7", "4.2b1", "4.2rc1", "4.2", "4.1.8", "4.1.9", "4.2.1", "3.2.19", "4.2.2", "4.2.3", "3.2.20", "4.1.10", "4.2.4", "3.2.21", "4.2.5", "4.1.11", "4.1.12", "3.2.22", "4.2.6", "3.2.23", "4.1.13", "4.2.7", "4.2.8", "4.2.9", "3.2.24", "4.2.10", "4.2.11", "3.2.25", "4.2.12", "4.2.13", "4.2.14", "4.2.15", "4.2.16", "4.2.17", "4.2.18", "4.2.19", "4.2.20", "4.2.21", "4.2.22", "4.2.23", "4.2.24", "4.2.25", "5.0a1", "5.0b1", "5.0rc1", "5.0", "5.0.1", "5.0.2", "5.0.3", "5.0.4", "5.0.5", "5.0.6", "5.1a1", "5.1b1", "5.0.7", "5.1rc1", "5.0.8", "5.1", "5.1.1", "5.0.9", "5.1.2", "5.1.3", "5.0.10", "5.1.4", "5.0.11", "5.1.5", "5.0.12", "5.1.6", "5.1.7", "5.0.13", "5.1.8", "5.0.14", "5.1.9", "5.1.10", "5.1.11", "5.1.12", "5.1.13", "5.2a1", "5.2b1", "5.2rc1", "5.2", "5.2.1", "5.2.2", "5.2.3", "5.2.4", "5.2.5", "5.2.6", "5.2.7"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
Published date: 2019-01-04T17:50:07Z
CVE: CVE-2018-7536
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in two regular expressions (only one regular expression for Django 1.8.x). The urlize() function is used to implement the urlize and urlizetrunc template filters, which were thus vulnerable.
Affected versions: ["1.8", "1.8.1", "1.8.10", "1.8.11", "1.8.12", "1.8.13", "1.8.14", "1.8.15", "1.8.16", "1.8.17", "1.8.18", "1.8.2", "1.8.3", "1.8.4", "1.8.5", "1.8.6", "1.8.7", "1.8.8", "1.8.9", "1.11", "1.11.1", "1.11.10", "1.11.2", "1.11.3", "1.11.4", "1.11.5", "1.11.6", "1.11.7", "1.11.8", "1.11.9", "2.0", "2.0.1", "2.0.2"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
Published date: 2020-01-16T22:35:12Z
CVE: CVE-2019-19844
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)
Affected versions: ["1.4.22", "1.4.7", "1.6.10", "1.9.11", "1.11.1", "1.4", "1.6.3", "1.8.1", "1.8.15", "1.0.3", "1.11.24", "1.4.16", "1.4.17", "1.7.11", "1.7.8", "1.7.9", "1.8.17", "1.10rc1", "1.11.14", "1.11.23", "1.2", "1.2.2", "1.3.4", "1.7.10", "1.8.16", "1.8.18", "1.8.6", "1.5.6", "1.6.4", "1.8.2", "1.9", "1.2.4", "1.7.6", "1.7.7", "1.8.5", "1.0.2", "1.1.3", "1.1.4", "1.10.1", "1.11.3", "1.5.3", "1.11.18", "1.4.8", "1.8", "1.0.4", "1.11.22", "1.2.5", "1.4.10", "1.4.12", "1.6.1", "1.8.10", "1.8.13", "1.10b1", "1.9.8", "1.2.6", "1.3", "1.5.1", "1.5.7", "1.6.11", "1.9.1", "1.11.12", "1.11.8", "1.11.9", "1.11rc1", "1.3.7", "1.7.2", "1.8.9", "1.9.9", "1.0.1", "1.10", "1.11.26", "1.5.5", "1.6.6", "1.11.15", "1.4.19", "1.6", "1.10.8", "1.11.2", "1.4.11", "1.7.1", "1.10.4", "1.4.14", "1.4.20", "1.10.5", "1.10a1", "1.11", "1.11.25", "1.11.4", "1.11.5", "1.4.13", "1.4.3", "1.6.8", "1.10.6", "1.4.5", "1.6.7", "1.8.11", "1.11.7", "1.3.6", "1.11.13", "1.2.3", "1.3.2", "1.4.4", "1.5.8", "1.9.3", "1.9.4", "1.8.8", "1.9.12", "1.10.2", "1.11.16", "1.11.17", "1.5.4", "1.6.9", "1.1", "1.10.3", "1.10.7", "1.11b1", "1.4.6", "1.5.11", "1.9.13", "1.8.7", "1.9.5", "1.8.3", "1.9.7", "1.2.7", "1.5.2", "1.6.5", "1.1.2", "1.4.18", "1.5.10", "1.7.3", "1.7.4", "1.11.20", "1.4.9", "1.5.12", "1.3.5", "1.4.15", "1.11.21", "1.11a1", "1.4.1", "1.5.9", "1.7", "1.9.2", "1.8.12", "1.8.4", "1.1.1", "1.11.10", "1.11.11", "1.3.3", "1.4.21", "1.6.2", "1.11.6", "1.2.1", "1.3.1", "1.4.2", "1.5", "1.7.5", "1.8.19", "1.9.10", "1.8.14", "1.9.6"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
Published date: 2019-02-12T15:36:37Z
CVE: CVE-2019-6975
Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function.
Affected versions: ["2.1", "2.1.1", "2.1.2", "2.1.3", "2.1.4", "2.1.5", "2.0", "2.0.1", "2.0.10", "2.0.2", "2.0.3", "2.0.4", "2.0.5", "2.0.6", "2.0.7", "2.0.8", "2.0.9", "1.0.1", "1.0.2", "1.0.3", "1.0.4", "1.1", "1.1.1", "1.1.2", "1.1.3", "1.1.4", "1.10", "1.10.1", "1.10.2", "1.10.3", "1.10.4", "1.10.5", "1.10.6", "1.10.7", "1.10.8", "1.10a1", "1.10b1", "1.10rc1", "1.11", "1.11.1", "1.11.10", "1.11.11", "1.11.12", "1.11.13", "1.11.14", "1.11.15", "1.11.16", "1.11.17", "1.11.18", "1.11.2", "1.11.3", "1.11.4", "1.11.5", "1.11.6", "1.11.7", "1.11.8", "1.11.9", "1.11a1", "1.11b1", "1.11rc1", "1.2", "1.2.1", "1.2.2", "1.2.3", "1.2.4", "1.2.5", "1.2.6", "1.2.7", "1.3", "1.3.1", "1.3.2", "1.3.3", "1.3.4", "1.3.5", "1.3.6", "1.3.7", "1.4", "1.4.1", "1.4.10", "1.4.11", "1.4.12", "1.4.13", "1.4.14", "1.4.15", "1.4.16", "1.4.17", "1.4.18", "1.4.19", "1.4.2", "1.4.20", "1.4.21", "1.4.22", "1.4.3", "1.4.4", "1.4.5", "1.4.6", "1.4.7", "1.4.8", "1.4.9", "1.5", "1.5.1", "1.5.10", "1.5.11", "1.5.12", "1.5.2", "1.5.3", "1.5.4", "1.5.5", "1.5.6", "1.5.7", "1.5.8", "1.5.9", "1.6", "1.6.1", "1.6.10", "1.6.11", "1.6.2", "1.6.3", "1.6.4", "1.6.5", "1.6.6", "1.6.7", "1.6.8", "1.6.9", "1.7", "1.7.1", "1.7.10", "1.7.11", "1.7.2", "1.7.3", "1.7.4", "1.7.5", "1.7.6", "1.7.7", "1.7.8", "1.7.9", "1.8", "1.8.1", "1.8.10", "1.8.11", "1.8.12", "1.8.13", "1.8.14", "1.8.15", "1.8.16", "1.8.17", "1.8.18", "1.8.19", "1.8.2", "1.8.3", "1.8.4", "1.8.5", "1.8.6", "1.8.7", "1.8.8", "1.8.9", "1.9", "1.9.1", "1.9.10", "1.9.11", "1.9.12", "1.9.13", "1.9.2", "1.9.3", "1.9.4", "1.9.5", "1.9.6", "1.9.7", "1.9.8", "1.9.9"]
Secure versions: [5.2.16, 5.2.17, 6.0.7, 6.0.8, 6.0a1, 6.0b1, 6.0rc1, 6.1, 6.1a1, 6.1b1, 6.1rc1]
Recommendation: Update to version 6.1.
441 Other Versions