Количество 900
Количество 900
GHSA-4mq2-gc4j-cmw6
Django Template Engine Vulnerable to XSS
GHSA-4c42-4rxm-x6qf
Django Denial of Service Vulnerability in the authentication framework
GHSA-4894-5vqc-6r2r
Django cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget
GHSA-46x4-9jmv-jc8p
Django Access Restrictions Bypass
GHSA-3jqw-crqj-w8qw
Denial of service in django
GHSA-3h9f-r86x-qvjx
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue.
GHSA-3f2c-jm6v-cr35
Django DNS Rebinding Vulnerability
GHSA-37hp-765x-j95x
Django open redirect and possible XSS attack via user-supplied numeric redirect URLs
GHSA-33mw-q7rj-mjwj
Django has Inefficient Algorithmic Complexity
GHSA-337x-4q8g-prc5
Improper Input Validation in Django
GHSA-2mcm-79hx-8fxw
Django has Observable Timing Discrepancy
GHSA-2hrw-hx67-34x6
Resource exhaustion in Django
GHSA-2gwj-7jmv-h26r
SQL Injection in Django
GHSA-2f9x-5v75-3qv4
Django Denial-of-service possibility in truncatechars_html and truncatewords_html template filters
GHSA-296w-6qhq-gf92
Django denial of service via file upload naming
GHSA-2655-q453-22f9
Django Allows Arbitrary URL Generation
CVE-2026-8404
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmed Badawe for reporting this issue.
CVE-2026-8404
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmed Badawe for reporting this issue.
CVE-2026-8404
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmed Badawe for reporting this issue.
CVE-2026-8404
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0 ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4mq2-gc4j-cmw6 Django Template Engine Vulnerable to XSS | CVSS3: 9.3 | 0% Низкий | больше 2 лет назад | |
GHSA-4c42-4rxm-x6qf Django Denial of Service Vulnerability in the authentication framework | CVSS3: 7.5 | 3% Низкий | около 4 лет назад | |
GHSA-4894-5vqc-6r2r Django cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget | CVSS3: 6.1 | 3% Низкий | около 4 лет назад | |
GHSA-46x4-9jmv-jc8p Django Access Restrictions Bypass | CVSS3: 5.5 | 2% Низкий | около 4 лет назад | |
GHSA-3jqw-crqj-w8qw Denial of service in django | CVSS3: 7.5 | 3% Низкий | около 8 лет назад | |
GHSA-3h9f-r86x-qvjx An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue. | CVSS3: 3.1 | 0% Низкий | 24 дня назад | |
GHSA-3f2c-jm6v-cr35 Django DNS Rebinding Vulnerability | CVSS3: 8.1 | 6% Низкий | около 4 лет назад | |
GHSA-37hp-765x-j95x Django open redirect and possible XSS attack via user-supplied numeric redirect URLs | CVSS3: 6.1 | 2% Низкий | больше 7 лет назад | |
GHSA-33mw-q7rj-mjwj Django has Inefficient Algorithmic Complexity | 1% Низкий | 6 месяцев назад | ||
GHSA-337x-4q8g-prc5 Improper Input Validation in Django | CVSS3: 6.5 | 3% Низкий | больше 7 лет назад | |
GHSA-2mcm-79hx-8fxw Django has Observable Timing Discrepancy | 1% Низкий | 6 месяцев назад | ||
GHSA-2hrw-hx67-34x6 Resource exhaustion in Django | CVSS3: 7.5 | 63% Средний | больше 3 лет назад | |
GHSA-2gwj-7jmv-h26r SQL Injection in Django | CVSS3: 9.8 | 19% Средний | больше 4 лет назад | |
GHSA-2f9x-5v75-3qv4 Django Denial-of-service possibility in truncatechars_html and truncatewords_html template filters | CVSS3: 5.3 | 4% Низкий | больше 7 лет назад | |
GHSA-296w-6qhq-gf92 Django denial of service via file upload naming | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-2655-q453-22f9 Django Allows Arbitrary URL Generation | CVSS3: 7.5 | 4% Низкий | около 4 лет назад | |
CVE-2026-8404 An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmed Badawe for reporting this issue. | CVSS3: 3.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-8404 An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmed Badawe for reporting this issue. | CVSS3: 3.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-8404 An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmed Badawe for reporting this issue. | CVSS3: 3.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-8404 An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0 ... | CVSS3: 3.1 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу