© 2025-2026 PySpect
First version without a known vulnerability: 6.1a1
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
Fixed in: 5.2.17, 6.0.8
Django: cache middleware may expose private responses when unrelated request cookies are present
Fixed in: 5.2.16, 6.0.7
Django: DomainNameValidator permits newline characters that may enable HTTP header injection
Fixed in: 5.2.16, 6.0.7
Django: GDALRaster may over-read heap memory when constructed from bytes
Fixed in: 5.2.16, 6.0.7
Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
Fixed in: 5.2.15, 6.0.6
Django: has_vary_header may expose cached responses when Vary values contain whitespace
Fixed in: 5.2.15, 6.0.6
Django: signed cookies are vulnerable to salt namespace collisions
Fixed in: 5.2.15, 6.0.6
Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
Fixed in: 5.2.15, 6.0.6
Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary
Fixed in: 5.2.15, 6.0.6
Django Uses Cache Containing Sensitive Information
Fixed in: 6.0.5, 5.2.14
Django has an Improper Handling of Length Parameter Inconsistency
Fixed in: 6.0.5, 5.2.14
Django Uses Persistent Cookies Containing Sensitive Information
Fixed in: 6.0.5, 5.2.14
Django vulnerable to privilege abuse in ModelAdmin.list_editable
Fixed in: 6.0.4, 5.2.13, 4.2.30
Django vulnerable to ASGI header spoofing via underscore/hyphen conflation
Fixed in: 6.0.4, 5.2.13, 4.2.30
Django vulnerable to privilege abuse in GenericInlineModelAdmin
Fixed in: 6.0.4, 5.2.13, 4.2.30
Django has potential DoS via MultiPartParser through crafted multipart uploads
Fixed in: 6.0.4, 5.2.13, 4.2.30
Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit
Fixed in: 6.0.4, 5.2.13, 4.2.30
Django vulnerable to Uncontrolled Resource Consumption
Fixed in: 6.0.3, 5.2.12, 4.2.29
Django has a Race Condition vulnerability
Fixed in: 6.0.3, 5.2.12, 4.2.29
Django has an SQL Injection issue
Fixed in: 6.0.2, 5.2.11, 4.2.28
Django has an SQL Injection issue
Fixed in: 6.0.2, 5.2.11, 4.2.28
Django has Observable Timing Discrepancy
Fixed in: 6.0.2, 5.2.11, 4.2.28
Django has Inefficient Algorithmic Complexity
Fixed in: 6.0.2, 5.2.11, 4.2.28
Django has Inefficient Algorithmic Complexity
Fixed in: 6.0.2, 5.2.11, 4.2.28
Django has an SQL Injection issue
Fixed in: 6.0.2, 5.2.11, 4.2.28
Django is vulnerable to SQL injection in column aliases
Fixed in: 5.2.9, 5.1.15, 4.2.27
Django is vulnerable to DoS via XML serializer text extraction
Fixed in: 5.2.9, 5.1.15, 4.2.27
Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
Fixed in: 5.2.8, 5.1.14, 4.2.26
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
Fixed in: 5.2.8, 5.1.14, 4.2.26
Django vulnerable to partial directory traversal via archives
Fixed in: 4.2.25, 5.1.13, 5.2.7
Django vulnerable to SQL injection in column aliases
Fixed in: 4.2.25, 5.1.13, 5.2.7
Django is subject to SQL injection through its column aliases
Fixed in: 4.2.24, 5.1.12, 5.2.6
Django Improper Output Neutralization for Logs vulnerability
Fixed in: 5.2.2, 5.1.10, 4.2.22
Django has a denial-of-service possibility in strip_tags()
Fixed in: 4.2.21, 5.1.9, 5.2.1
Django Potential Denial of Service (DoS) on Windows
Fixed in: 5.0.14, 5.1.8
Django vulnerable to Allocation of Resources Without Limits or Throttling
Fixed in: 4.2.20, 5.0.13, 5.1.7
Django has a potential denial-of-service vulnerability in IPv6 validation
Fixed in: 5.1.5, 5.0.11, 4.2.18
Django denial-of-service in django.utils.html.strip_tags()
Fixed in: 5.1.4, 4.2.17, 5.0.10
Django SQL injection in HasKey(lhs, rhs) on Oracle
Fixed in: 5.0.10, 5.1.4, 4.2.17
Django vulnerable to denial-of-service attack via the urlize() and urlizetrunc() template filters
Fixed in: 5.1.1, 5.0.9, 4.2.16
Django allows enumeration of user e-mail addresses
Fixed in: 5.1.1, 5.0.9, 4.2.16
Django vulnerable to a denial-of-service attack
Fixed in: 5.0.8, 4.2.15
Django memory consumption vulnerability
Fixed in: 5.0.8, 4.2.15
Django SQL injection vulnerability
Fixed in: 5.0.8, 4.2.15
Django vulnerable to denial-of-service attack
Fixed in: 5.0.8, 4.2.15
Django Path Traversal vulnerability
Fixed in: 5.0.7, 4.2.14
Django vulnerable to Denial of Service
Fixed in: 5.0.7, 4.2.14
Django vulnerable to Denial of Service
Fixed in: 4.2.14, 5.0.7
Django vulnerable to user enumeration attack
Fixed in: 5.0.7, 4.2.14
Regular expression denial-of-service in Django
Fixed in: 3.2.25, 4.2.11, 5.0.3
Django denial-of-service attack in the intcomma template filter
Fixed in: 3.2.24, 4.2.10, 5.0.2
Django Denial-of-service in django.utils.text.Truncator
Fixed in: 3.2.22, 4.1.12, 4.2.6
Django Denial of service vulnerability in django.utils.encoding.uri_to_iri
Fixed in: 3.2.21, 4.1.11, 4.2.5
Django potential denial of service vulnerability in UsernameField on Windows
Fixed in: 3.2.23, 4.1.13, 4.2.7
Django has regular expression denial of service vulnerability in EmailValidator/URLValidator
Fixed in: 3.2.20, 4.1.10, 4.2.3
Django bypasses validation when using one form field to upload multiple files
Fixed in: 3.2.19, 4.1.9, 4.2.1
Resource exhaustion in Django
Fixed in: 3.2.18, 4.1.7, 4.0.10
Django contains Uncontrolled Resource Consumption via cached header
Fixed in: 3.2.17, 4.0.9, 4.1.6
Django denial-of-service vulnerability in internationalized URLs
Fixed in: 3.2.16, 4.0.8, 4.1.2, 5b6b257fa7ec37ff27965358800c67e2dd11c924
Django vulnerable to Reflected File Download attack
Fixed in: 3.2.15, 4.0.7
Django `Trunc()` and `Extract()` database functions vulnerable to SQL Injection
Fixed in: 3.2.14, 4.0.6
Django Image Field Vulnerable to Image Decompression Bombs
Fixed in: 1.3.2, 1.4.1
Django vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer
Fixed in: 1.3.2, 1.4.1
Django Allows Redirect via Data URL
Fixed in: 1.3.2, 1.4.1
Django Allows Arbitrary URL Generation
Fixed in: 1.3.4, 1.4.2, 9305c0e12d43c4df999c3301a1f0c742264a657e, b45c377f8f488955e0c7069cad3f3dd21910b071, 92d3430f12171f16f566c9050c40feefb830a4a3
XML Entity Expansion (XEE) in Django
Fixed in: 1.3.6, 1.4.4
XML External Entity (XXE) in Django
Fixed in: 1.3.6, 1.4.4
Django Directory Traversal via ssi template tag
Fixed in: 1.4.7, 1.5.3
Django Denial of Service Vulnerability in the authentication framework
Fixed in: 1.4.8, 1.5.4
Django Access Restrictions Bypass
Fixed in: 1.9.2
Django Cross-site Scripting Vulnerability
Fixed in: 1.7.6, 1.8b2
Django allows user sessions hijacking via an empty string in the session key
Fixed in: 1.8.2
Django settings leak in date template filter
Fixed in: 1.7.11, 1.8.7, 1.9rc2, 316bc3fc9437c5960c24baceb93c73f1939711e4
Django WSGI Header Spoofing Vulnerability
Fixed in: 1.4.18, 1.6.10, 1.7.3
Django database denial-of-service with ModelMultipleChoiceField
Fixed in: 1.6.10, 1.7.3, 1.4.18
Django DoS in django.views.static.serve
Fixed in: 1.4.18, 1.6.10, 1.7.3
Django Cross-site Scripting Vulnerability
Fixed in: 1.4.18, 1.6.10, 1.7.3
Denial-of-service possibility in logout() view by filling session store
Fixed in: 1.7.10, 1.4.22
Django Reuses Cached CSRF Token
Fixed in: 1.4.11, 1.5.6, 1.6.3
Code Injection in Django
Fixed in: 1.4.11, 1.5.6, 1.6.3
Django Vulnerable to MySQL Injection
Fixed in: 1.4.11, 1.5.6, 1.6.3
Django Vulnerable to Cache Poisoning
Fixed in: 1.4.13, 1.5.8, 1.6.5, 1.7b4
Django cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget
Fixed in: 1.5.2, 90363e388c61874add3f3557ee654a996ec75d78, cbe6d5568f4f5053ed7228ca3c3d0cce77cf9560
Django User Enumeration Vulnerability
Fixed in: 1.8.10, 1.9.3, 67b46ba7016da2d259c1ecc7d666d11f5e1cfaab
Django XSS Vulnerability
Fixed in: 1.8.10, 1.9.3, c5544d289233f501917e25970c03ed444abbd4f0
Django ReDoS in validators.URLValidator
Fixed in: 1.8.3
Django Vulnerable to HTTP Response Splitting Attack
Fixed in: 1.4.21, 1.7.9, 1.8.3
Django denial of service via empty session record creation
Fixed in: 1.8.4, 1.7.10, 1.4.22
Django DNS Rebinding Vulnerability
Fixed in: 1.8.16, 1.9.11, 1.10.3
Django user with hardcoded password created when running tests on Oracle
Fixed in: 1.10.3, 1.9.11, 1.8.16
Django cross-site scripting (XSS) vulnerability via is_safe_url function
Fixed in: 1.4.6, 1.5.2, ec67af0bd609c412b76eaa4cc89968a2a8e5ad6a, ae3535169af804352517b7fea94a42a1c9c4b762, 1a274ccd6bc1afbdac80344c9b6e5810c1162b5f
Django CSRF Protection Bypass
Fixed in: 1.8.15, 1.9.10
Django Vulnerable to Cache Poisoning
Fixed in: 1.2.7, 1.3.1
Django Might Allow CSRF Requests via URL Verification
Fixed in: 1.2.7, 1.3.1
Django Cross-site scripting Vulnerability
Fixed in: 1.8.14, 1.9.8, 1.10rc1, d03bf6fe4e9bf5b07de62c1a271c4b41a7d3d158, f68e5a99164867ab0e071a936470958ed867479d
Django Allows Open Redirects
Fixed in: 1.4.13, 1.5.8, 1.6.5, 1.7b4
Django Middleware Enables Session Hijacking
Fixed in: 1.4.14, 1.5.9, 1.6.6, 1.7c3
Django Incorrectly Validates URLs
Fixed in: 1.4.14, 1.5.9, 1.6.6
Django data leakage via querystring manipulation in admin
Fixed in: 1.4.14, 1.5.9, 1.6.6, 1.7c3, 2b31342cdf14fc20e07c43d258f1e7334ad664a6
Django Denial-of-service possibility with strip_tags
Fixed in: 1.6.11, 1.7.7, 1.8c1
Django cross-site scripting (XSS) attack via user-supplied redirect URLs
Fixed in: 1.4.20, 1.6.11, 1.7.7, 1.8c1
Django denial of service via file upload naming
Fixed in: 1.4.14, 1.5.9, 1.6.6
Django Data leakage via admin history log
Fixed in: 1.3.6, 1.4.4
Django is vulnerable to Denial of Service attack in formset
Fixed in: 1.3.6, 1.4.4
Django Regex Algorithmic Complexity Causes Denial of Service
Fixed in: 1.0.4, 1.1.1
Django Admin Media Handler Vulnerable to Directory Traversal
Fixed in: 0.96.4, 1.0.3, 1.1
Django cross-site request forgery (CSRF) vulnerability
Fixed in: 0.91.3, 0.95.4, 0.96.3, 1.1
Django Cross-site scripting (XSS) vulnerability
Fixed in: 0.91.2, 0.95.3, 0.96.2, 1.1
Django vulnerable to Denial of Service via i18n middleware component
Fixed in: 0.96.1, 0.95.2, 0.91.1, 1.1
Django Improper Access Control
Fixed in: 1.0
Django Arbitrary Code Execution
Fixed in: 1.0
SQL Injection in Django
Fixed in: 2.2.28, 3.2.13, 4.0.4
SQL Injection in Django
Fixed in: 2.2.28, 3.2.13, 4.0.4
Cross-site Scripting in Django
Fixed in: 2.2.27, 3.2.12, 4.0.2
Infinite Loop in Django
Fixed in: 2.2.27, 3.2.12, 4.0.2
Information disclosure in Django
Fixed in: 2.2.26, 3.2.11, 4.0.1
Directory-traversal in Django
Fixed in: 2.2.26, 3.2.11, 4.0.1
Denial-of-service in Django
Fixed in: 2.2.26, 3.2.11, 4.0.1
Potential bypass of an upstream access control based on URL paths in Django
Fixed in: 2.2.25, 3.1.14, 3.2.10
SQL Injection in Django
Fixed in: 3.2.5, 3.1.13
Django Access Control Bypass possibly leading to SSRF, RFI, and LFI attacks
Fixed in: 2.2.24, 3.1.12, 3.2.4
Path Traversal in Django
Fixed in: 2.2.24, 3.1.12, 3.2.4
Header injection possible in Django
Fixed in: 2.2.22, 3.1.10, 3.2.2
Path Traversal in Django
Fixed in: 2.2.21, 3.1.9, 3.2.1
Directory Traversal in Django
Fixed in: 2.2.20, 3.0.14, 3.1.8
Django Incorrect Default Permissions
Fixed in: 2.2.16, 3.0.10, 3.1.1
Django Incorrect Default Permissions
Fixed in: 2.2.16, 3.0.10, 3.1.1
Django Directory Traversal via archive.extract
Fixed in: 2.2.18, 3.1.6, 3.0.12
XSS in Django
Fixed in: 2.2.13, 3.0.7
Data leakage via cache key collision in Django
Fixed in: 2.2.13, 3.0.7
SQL injection in Django
Fixed in: 1.11.29, 2.2.11, 3.0.4
SQL injection in Django
Fixed in: 1.11.28, 2.2.10, 3.0.3, eb31d845323618d688ad429479c6dda973056136
Django Potential account hijack via password reset form
Fixed in: 1.11.27, 2.2.9, 3.0.1
Django allows unintended model editing
Fixed in: 2.1.15, 2.2.8
SQL Injection in Django
Fixed in: 1.11.23, 2.1.11, 2.2.4
Django Denial-of-service in strip_tags()
Fixed in: 1.11.23, 2.1.11, 2.2.4
Uncontrolled Recursion in Django
Fixed in: 1.11.23, 2.1.11, 2.2.4
Django Denial-of-service in django.utils.text.Truncator
Fixed in: 1.11.23, 2.1.11, 2.2.4
Django Denial-of-service by filling session store
Fixed in: 1.4.21, 1.7.9, 1.8.3
Django Incorrect HTTP detection with reverse-proxy connecting via HTTPS
Fixed in: 2.1.10, 2.2.3, 1.11.22
Django Cross-site Scripting in AdminURLFieldWidget
Fixed in: 1.11.21, 2.1.9, 2.2.2
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
Fixed in: 3.4.0, 4.3.4, 2.1.9, 2.2.2, 1.19.0
Uncontrolled Memory Consumption in Django
Fixed in: 1.11.19, 2.0.11, 2.1.6, 2.0.12, 2.1.7
Improper Input Validation in Django
Fixed in: 1.11.18, 2.0.10, 2.1.5
Django vulnerable to XSS on 500 pages
Fixed in: 1.10.8, 1.11.5
Django open redirect and possible XSS attack via user-supplied numeric redirect URLs
Fixed in: 1.10.7, 1.9.13, 1.8.18
Django open redirect
Fixed in: 1.10.7, 1.9.13, 1.8.18
Django denial-of-service possibility in urlize and urlizetrunc template filters
Fixed in: 2.0.3, 1.11.11, 1.8.19
Django Denial-of-service possibility in truncatechars_html and truncatewords_html template filters
Fixed in: 2.0.3, 1.11.11, 1.8.19
Django open redirect
Fixed in: 2.0.8, 1.11.15
Django vulnerable to information leakage in AuthenticationForm
Fixed in: 2.0.2, 1.11.10
Django allows unprivileged users to read the password hashes of arbitrary accounts
Fixed in: 2.1.2
Cross-site scripting in django
Fixed in: 1.1.4, 1.2.5
Cross-site scripting in django
Fixed in: 1.2.2
Session manipulation in Django
Fixed in: 1.2.7, 1.3.1
Directory traversal in Django
Fixed in: 1.1.4, 1.2.5
Improper date handling in Django
Fixed in: 1.1.3, 1.2.4
Improper query string handling in Django
Fixed in: 1.1.3, 1.2.4
Denial of service in django
Fixed in: 1.2.7, 1.3.1
Django Cross-Site Request Forgery vulnerability
Fixed in: 1.2.7, 1.3.1
Cross-site request forgery in Django
Fixed in: 1.1.4, 1.2.5