Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-07736

Опубликовано: 03 мар. 2026
Источник: fstec
CVSS3: 3.7
CVSS2: 2.6
EPSS Низкий

Описание

Уязвимость программной платформы для веб-приложений Django связана с ошибками синхронизации при использовании общего ресурса. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, вызвать отказ в обслуживании

Вендор

ООО «Ред Софт»
Red Hat Inc.
Django Software Foundation

Наименование ПО

РЕД ОС
Red Hat Satellite
Discovery
Ansible Automation Platform
Django

Версия ПО

7.3 (РЕД ОС)
6 (Red Hat Satellite)
8.0 (РЕД ОС)
2 (Discovery)
2 (Ansible Automation Platform)
от 6.0 до 6.0.3 (Django)
от 5.2 до 5.2.12 (Django)
от 4.2 до 4.2.29 (Django)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Низкий уровень опасности (базовая оценка CVSS 2.0 составляет 2,6)
Низкий уровень опасности (базовая оценка CVSS 3.1 составляет 3,7)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для Django:
https://www.djangoproject.com/weblog/2026/mar/03/security-releases/
https://github.com/django/django/commit/019e44f67a8dace67b786e2818938c8691132988
https://github.com/django/django/commit/264d5c70ef3281a8869cb2ad45a3a52d5adbe790
https://github.com/django/django/commit/b07ed2a1e445efde54fc64cb8c37e0f4f7fe53e5
https://github.com/django/django/commit/54b50bf7d6dcbf02d4c01f853627cc9299d4934d
Для РедОС:
https://redos.red-soft.ru/search/?iblock_id=&q=CVE-2026-25674
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-25674#cve-affected-packages

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 26%
0.00341
Низкий

3.7 Low

CVSS3

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 3.7
redos
3 месяца назад

Уязвимость python-django

CVSS3: 3.7
ubuntu
5 месяцев назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's temporary `umask` change affects other threads in multi-threaded environments. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 3.7
redhat
5 месяцев назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's temporary `umask` change affects other threads in multi-threaded environments. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 3.7
nvd
5 месяцев назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's temporary `umask` change affects other threads in multi-threaded environments. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 3.7
debian
5 месяцев назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4. ...

EPSS

Процентиль: 26%
0.00341
Низкий

3.7 Low

CVSS3

2.6 Low

CVSS2