Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

5.26.020252026202720282029

Недавние уязвимости Django

Количество 895

github логотип

GHSA-5hrc-gvxj-w55p

3 месяца назад

Django Uses Cache Containing Sensitive Information

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-w26r-rmm8-9c29

3 месяца назад

Django has an Improper Handling of Length Parameter Inconsistency

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-7h2m-m8vj-598h

3 месяца назад

Django Uses Persistent Cookies Containing Sensitive Information

EPSS: Низкий
debian логотип

CVE-2026-6907

3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `dj ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-6907

3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). This can lead to private data being stored and served. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmad Sadeddin for reporting this issue.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2026-5766

3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASG ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-5766

3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and causing service degradation. As a reminder, Django expects a limit to be configured at the web server level rather than solely relying on `FILE_UPLOAD_MAX_MEMORY_SIZE`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Kyle Agronick for reporting this issue.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-35192

3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Res ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-35192

3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-35192

3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-5hrc-gvxj-w55p

Django Uses Cache Containing Sensitive Information

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-w26r-rmm8-9c29

Django has an Improper Handling of Length Parameter Inconsistency

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-7h2m-m8vj-598h

Django Uses Persistent Cookies Containing Sensitive Information

1%
Низкий
3 месяца назад
debian логотип
CVE-2026-6907

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `dj ...

CVSS3: 4.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-6907

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). This can lead to private data being stored and served. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmad Sadeddin for reporting this issue.

CVSS3: 4.3
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-5766

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASG ...

CVSS3: 5.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-5766

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and causing service degradation. As a reminder, Django expects a limit to be configured at the web server level rather than solely relying on `FILE_UPLOAD_MAX_MEMORY_SIZE`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Kyle Agronick for reporting this issue.

CVSS3: 5.3
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-35192

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Res ...

CVSS3: 6.5
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-35192

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

CVSS3: 6.5
1%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-35192

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

CVSS3: 6.5
1%
Низкий
3 месяца назад

Уязвимостей на страницу


Поделиться