OSPulse

Is django healthy, maintained, and safe?

55/ 100
djangov6.1.1
Medium riskconfidence: Highview on pypi.org

No — Django carries 16 unpatched critical advisories and should not be adopted without a remediation plan.

vital-signs traceirregular · weakening

The verdict

On the OSPulse health scale, Django lands at 55/100 — medium risk, computed deterministically from live PyPI release history, and the OSV vulnerability database. No — Django carries 16 unpatched critical advisories and should not be adopted without a remediation plan.

Its most recent release shipped on 2 September 2026 — 5 days ago — so development is clearly active. Across 433 releases the cadence has been steady, which is a good sign of an ongoing maintenance rhythm. PyPI doesn't expose a reliable maintainer count, so bus-factor isn't scored here — treat maintenance depth as unknown rather than assumed.

OSV lists 321 known advisories for Django, including 16 critical and 64 high. Open critical advisories are the strongest possible signal to pin to a patched version, replace, or fork before shipping. Each advisory is listed with its OSV/GHSA identifier below.

Django is usable but carries real signals — pin versions, watch for new advisories, and keep a fallback in mind. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own requirements.txt through the free health check, or have OSPulse monitor your whole dependency tree continuously.

Evidence trail — deterministic, auditable

Last release recency
5 days ago · active
Release cadence
steady · typical gap ~6d
Maintainer bus factor
not available from PyPI — not penalised
Known vulnerabilities (OSV)
321 advisories · 16 critical · 64 high
-45
Package age
16.3 years · 433 releases

Known vulnerabilities (321)

  • GHSA-2655-q453-22f9HIGHCVE-2012-4520PYSEC-2012-7

    Django Allows Arbitrary URL Generation

  • GHSA-296w-6qhq-gf92HIGHCVE-2014-0481PYSEC-2014-5

    Django denial of service via file upload naming

  • GHSA-2f9x-5v75-3qv4LOWCVE-2018-7537PYSEC-2018-6

    Django Denial-of-service possibility in truncatechars_html and truncatewords_html template filters

  • GHSA-2gwj-7jmv-h26rCRITICALBIT-django-2022-28346CVE-2022-28346PYSEC-2022-190

    SQL Injection in Django

  • GHSA-2hrw-hx67-34x6HIGHBIT-django-2023-24580CVE-2023-24580PYSEC-2023-13

    Resource exhaustion in Django

  • GHSA-2m34-jcjv-45xfMODERATEBIT-django-2020-13596CVE-2020-13596PYSEC-2020-32

    XSS in Django

  • GHSA-2mcm-79hx-8fxwLOWBIT-django-2025-13473CVE-2025-13473PYSEC-2026-42

    Django has Observable Timing Discrepancy

  • GHSA-337x-4q8g-prc5HIGHCVE-2019-3498PYSEC-2019-17

    Improper Input Validation in Django

  • GHSA-33mw-q7rj-mjwjLOWBIT-django-2025-14550CVE-2025-14550PYSEC-2026-43

    Django has Inefficient Algorithmic Complexity

  • GHSA-37hp-765x-j95xMODERATECVE-2017-7233PYSEC-2017-9

    Django open redirect and possible XSS attack via user-supplied numeric redirect URLs

  • GHSA-3f2c-jm6v-cr35CRITICALCVE-2016-9014PYSEC-2016-18

    Django DNS Rebinding Vulnerability

  • GHSA-3gh2-xw74-jmcwHIGHBIT-django-2020-9402CVE-2020-9402PYSEC-2020-36

    SQL injection in Django

  • GHSA-3h9f-r86x-qvjxLOWBIT-django-2026-48588CVE-2026-48588PYSEC-2026-2090

    Django: cache middleware may expose private responses when unrelated request cookies are present

  • GHSA-3jqw-crqj-w8qwHIGHCVE-2011-4137PYSEC-2011-2

    Denial of service in django

  • GHSA-46x4-9jmv-jc8pHIGHCVE-2016-2048PYSEC-2016-14

    Django Access Restrictions Bypass

  • GHSA-4894-5vqc-6r2rMODERATECVE-2013-4249PYSEC-2013-19

    Django cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget

  • GHSA-4c42-4rxm-x6qfHIGHCVE-2013-1443PYSEC-2013-18

    Django Denial of Service Vulnerability in the authentication framework

  • GHSA-4rrr-2h4v-f3j9LOWBIT-django-2026-1285CVE-2026-1285PYSEC-2026-45

    Django has Inefficient Algorithmic Complexity

  • GHSA-53qw-q765-4fwwHIGHBIT-django-2021-45115CVE-2021-45115PYSEC-2022-1

    Denial-of-service in Django

  • GHSA-54qj-48vx-cr9fMODERATECVE-2008-2302PYSEC-2008-1

    Django Cross-site scripting (XSS) vulnerability

  • GHSA-59w8-4wm2-4xw8HIGHCVE-2012-3443PYSEC-2012-3

    Django Image Field Vulnerable to Image Decompression Bombs

  • GHSA-5h2q-4hrp-v9rrHIGHCVE-2012-3444PYSEC-2012-4

    Django vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer

  • GHSA-5hg3-6c2f-f3wrMODERATECVE-2018-14574PYSEC-2018-2

    Django open redirect

  • GHSA-5hgc-2vfp-mqvcMODERATEBIT-django-2024-45230CVE-2024-45230PYSEC-2024-102

    Django vulnerable to denial-of-service attack via the urlize() and urlizetrunc() template filters

  • GHSA-5hrc-gvxj-w55pLOWBIT-django-2026-6907CVE-2026-6907PYSEC-2026-55

    Django Uses Cache Containing Sensitive Information

  • GHSA-5j2h-h5hg-3wf8HIGHCVE-2011-0696PYSEC-2011-10

    Cross-site request forgery in Django

  • GHSA-5mf9-h53q-7mhqMODERATEBIT-django-2026-33033CVE-2026-33033PYSEC-2026-48

    Django has potential DoS via MultiPartParser through crafted multipart uploads

  • GHSA-625g-gx8c-xcmgMODERATECVE-2014-0482PYSEC-2014-6

    Django Middleware Enables Session Hijacking

  • GHSA-6426-9fv3-65x8MODERATEBIT-django-2026-1312CVE-2026-1312PYSEC-2026-47

    Django has an SQL Injection issue

  • GHSA-6565-fg86-6jcxMODERATECVE-2015-2241PYSEC-2015-8

    Django Cross-site Scripting Vulnerability

  • GHSA-68w8-qjq3-2gfmMODERATEBIT-django-2021-33203CVE-2021-33203PYSEC-2021-98

    Path Traversal in Django

  • GHSA-6c3j-c64m-qhgqMODERATECVE-2019-11358DRUPAL-CORE-2019-006PYSEC-2026-628

    XSS in jQuery as used in Drupal, Backdrop CMS, and other products

  • GHSA-6c7v-2f49-8h26MODERATECVE-2019-12781PYSEC-2019-10

    Django Incorrect HTTP detection with reverse-proxy connecting via HTTPS

  • GHSA-6cw3-g6wv-c2xvHIGHBIT-django-2022-23833CVE-2022-23833PYSEC-2022-20

    Infinite Loop in Django

  • GHSA-6g95-x6cj-mg4vHIGHCVE-2015-0222PYSEC-2015-7

    Django database denial-of-service with ModelMultipleChoiceField

  • GHSA-6mx3-3vqg-hpp2MODERATECVE-2018-16984PYSEC-2018-3

    Django allows unprivileged users to read the password hashes of arbitrary accounts

  • GHSA-6r97-cj55-9hrqCRITICALCVE-2019-14234PYSEC-2019-13

    SQL Injection in Django

  • GHSA-6w2r-r2m5-xq5wHIGHBIT-django-2025-57833CVE-2025-57833PYSEC-2025-105

    Django is subject to SQL injection through its column aliases

  • GHSA-6wcr-wcqm-3mfhMODERATECVE-2015-8213PYSEC-2015-11

    Django settings leak in date template filter

  • GHSA-6wgp-fwfm-mxp3MODERATECVE-2015-3982PYSEC-2015-19

    Django allows user sessions hijacking via an empty string in the session key

  • GHSA-78vx-ggch-wghmCRITICALCVE-2012-3442PYSEC-2012-2

    Django Allows Redirect via Data URL

  • GHSA-795c-9xpc-xw6gMODERATEBIT-django-2024-41990CVE-2024-41990PYSEC-2024-68

    Django vulnerable to a denial-of-service attack

  • GHSA-7fq8-4pv5-5w5cMODERATECVE-2015-2317PYSEC-2015-9

    Django cross-site scripting (XSS) attack via user-supplied redirect URLs

  • GHSA-7g9h-c88w-r7h2CRITICALCVE-2011-0698PYSEC-2011-12

    Directory traversal in Django

  • GHSA-7h2m-m8vj-598hLOWBIT-django-2026-35192CVE-2026-35192PYSEC-2026-50

    Django Uses Persistent Cookies Containing Sensitive Information

  • GHSA-7h4p-27mh-hmrwMODERATEBIT-django-2023-41164CVE-2023-41164PYSEC-2023-225

    Django Denial of service vulnerability in django.utils.encoding.uri_to_iri

  • GHSA-7qfw-j7hp-v45gMODERATECVE-2015-0219PYSEC-2015-4

    Django WSGI Header Spoofing Vulnerability

  • GHSA-7rp2-fm2h-wchjMODERATECVE-2019-12308PYSEC-2019-79

    Django Cross-site Scripting in AdminURLFieldWidget

  • GHSA-7wph-fc4w-wqp2MODERATECVE-2010-4535PYSEC-2011-9

    Improper date handling in Django

  • GHSA-7xr5-9hcq-chf9MODERATEBIT-django-2025-48432CVE-2025-48432PYSEC-2025-47

    Django Improper Output Neutralization for Logs vulnerability

  • GHSA-8498-2h75-472jMODERATEBIT-django-2024-53907CVE-2024-53907PYSEC-2024-156

    Django denial-of-service in django.utils.html.strip_tags()

  • GHSA-89hj-xfx5-7q66HIGHCVE-2014-0473PYSEC-2014-2

    Django Reuses Cached CSRF Token

  • GHSA-8c5j-9r9f-c6w8HIGHBIT-django-2021-45116CVE-2021-45116PYSEC-2022-2

    Information disclosure in Django

  • GHSA-8cjm-8mp7-r2xfLOWBIT-django-2026-8404CVE-2026-8404PYSEC-2026-201

    Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling

  • GHSA-8j24-cjrq-gr2mMODERATEBIT-django-2025-32873CVE-2025-32873PYSEC-2025-37

    Django has a denial-of-service possibility in strip_tags()

  • GHSA-8m3r-rv5g-fcpqMODERATECVE-2011-0697PYSEC-2011-11

    Cross-site scripting in django

  • GHSA-8p8v-wh79-9r56HIGHBIT-django-2026-25673CVE-2026-25673PYSEC-2026-2448

    Django vulnerable to Uncontrolled Resource Consumption

  • GHSA-8qcx-xf44-272xMODERATEBIT-django-2026-53878CVE-2026-53878PYSEC-2026-2092

    Django: DomainNameValidator permits newline characters that may enable HTTP header injection

  • GHSA-8x94-hmjh-97hqHIGHBIT-django-2022-36359CVE-2022-36359PYSEC-2022-245

    Django vulnerable to Reflected File Download attack

  • GHSA-923m-gv2p-w5qpLOWBIT-django-2026-48587CVE-2026-48587PYSEC-2026-198

    Django: has_vary_header may expose cached responses when Vary values contain whitespace

  • GHSA-933h-hp56-hf7mHIGHBIT-django-2026-33034CVE-2026-33034PYSEC-2026-49

    Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit

  • GHSA-95rw-fx8r-36v6MODERATEBIT-django-2022-22818CVE-2022-22818PYSEC-2022-19

    Cross-site Scripting in Django

  • GHSA-9cwg-mhxf-hh59MODERATECVE-2013-6044PYSEC-2013-21

    Django cross-site scripting (XSS) vulnerability via is_safe_url function

  • GHSA-9jmf-237g-qf46HIGHBIT-django-2024-39330CVE-2024-39330PYSEC-2024-58

    Django Path Traversal vulnerability

  • GHSA-9r8w-6x8c-6jr9MODERATECVE-2017-12794PYSEC-2017-44

    Django vulnerable to XSS on 500 pages

  • GHSA-9v8h-57gv-qch6HIGHCVE-2007-5712PYSEC-2007-1

    Django vulnerable to Denial of Service via i18n middleware component

  • GHSA-9xg7-gg9m-rmq9HIGHCVE-2009-2659PYSEC-2009-3

    Django Admin Media Handler Vulnerable to Directory Traversal

  • GHSA-c4qh-4vgv-qc6gHIGHCVE-2019-14232PYSEC-2019-11

    Django Denial-of-service in django.utils.text.Truncator

  • GHSA-c8c8-9472-w52hMODERATECVE-2016-6186PYSEC-2016-2

    Django Cross-site scripting Vulnerability

  • GHSA-cqf7-ff9h-7967HIGHCVE-2015-5145PYSEC-2015-21

    Django ReDoS in validators.URLValidator

  • GHSA-crhf-3pfg-w68wMODERATEBIT-django-2026-53877CVE-2026-53877PYSEC-2026-2091

    Django: GDALRaster may over-read heap memory when constructed from bytes

  • GHSA-crhm-qpjc-cm64HIGHCVE-2016-7401PYSEC-2016-3

    Django CSRF Protection Bypass

  • GHSA-f6f8-9mx6-9mx2HIGHBIT-django-2024-39614CVE-2024-39614PYSEC-2024-59

    Django vulnerable to Denial of Service

  • GHSA-f7cm-ccfp-3q4rHIGHCVE-2014-0480PYSEC-2014-4

    Django Incorrectly Validates URLs

  • GHSA-fp6p-5xvw-m74fLOWCVE-2016-2513PYSEC-2016-16

    Django User Enumeration Vulnerability

  • GHSA-fr28-569j-53c4MODERATEBIT-django-2020-24584CVE-2020-24584PYSEC-2020-34

    Django Incorrect Default Permissions

  • GHSA-frmv-pr5f-9mcrCRITICALBIT-django-2025-64459CVE-2025-64459PYSEC-2025-108

    Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.

  • GHSA-fvgf-6h6h-3322MODERATEBIT-django-2021-3281CVE-2021-3281PYSEC-2021-9

    Django Directory Traversal via archive.extract

  • GHSA-fwr5-q9rx-294fHIGHCVE-2010-4534PYSEC-2011-8

    Improper query string handling in Django

  • GHSA-fxpg-gg9g-76gjMODERATECVE-2010-3082PYSEC-2010-12

    Cross-site scripting in django

  • GHSA-g8xg-jgj6-49r3MODERATECVE-2013-0306PYSEC-2013-17

    Django is vulnerable to Denial of Service attack in formset

  • GHSA-gv98-g628-m9x5MODERATECVE-2015-0220PYSEC-2015-5

    Django Cross-site Scripting Vulnerability

  • GHSA-gvg8-93h5-g6qqHIGHBIT-django-2026-1287CVE-2026-1287PYSEC-2026-46

    Django has an SQL Injection issue

  • GHSA-h4hv-m4h4-mhwgMODERATECVE-2017-7234PYSEC-2017-10

    Django open redirect

  • GHSA-h582-2pch-3xv3HIGHCVE-2015-5143PYSEC-2015-20

    Django Denial-of-service by filling session store

  • GHSA-h5jv-4p7w-64jgHIGHCVE-2019-14233PYSEC-2019-12

    Django Denial-of-service in strip_tags()

  • GHSA-h7pc-vwp9-298gLOWBIT-django-2026-6873CVE-2026-6873PYSEC-2026-199

    Django: signed cookies are vulnerable to salt namespace collisions

  • GHSA-h8gc-pgj2-vjm3HIGHBIT-django-2023-43665CVE-2023-43665PYSEC-2023-226

    Django Denial-of-service in django.utils.text.Truncator

  • GHSA-h95j-h2rv-qrg4HIGHCVE-2011-4140PYSEC-2011-5

    Django Cross-Site Request Forgery vulnerability

  • GHSA-hmr4-m2h5-33qxCRITICALBIT-django-2020-7471CVE-2020-7471PYSEC-2020-35

    SQL injection in Django

  • GHSA-hpr9-3m2g-3j9pHIGHBIT-django-2025-59681CVE-2025-59681PYSEC-2025-106

    Django vulnerable to SQL injection in column aliases

  • GHSA-hvmf-r92r-27hrHIGHCVE-2019-19118PYSEC-2019-15

    Django allows unintended model editing

  • GHSA-j3j3-jrfh-cm2wHIGHCVE-2015-2316PYSEC-2015-18

    Django Denial-of-service possibility with strip_tags

  • GHSA-jh3w-4vvf-mjgrHIGHBIT-django-2023-36053CVE-2023-36053PYSEC-2023-100

    Django has regular expression denial of service vulnerability in EmailValidator/URLValidator

  • GHSA-jh75-99hh-qvx9MODERATEBIT-django-2024-41989CVE-2024-41989PYSEC-2024-67

    Django memory consumption vulnerability

  • GHSA-jhjg-w2cp-5j44HIGHCVE-2015-0221PYSEC-2015-6

    Django DoS in django.views.static.serve

  • GHSA-jrh2-hc4r-7jwxMODERATEBIT-django-2021-45452CVE-2021-45452PYSEC-2022-3

    Directory-traversal in Django

  • GHSA-m6gj-h9gm-gw44HIGHBIT-django-2020-24583CVE-2020-24583PYSEC-2020-33

    Django Incorrect Default Permissions

  • GHSA-m9g8-fxxm-xg86HIGHBIT-django-2024-53908CVE-2024-53908PYSEC-2024-157

    Django SQL injection in HasKey(lhs, rhs) on Oracle

  • GHSA-mjgh-79qc-68w3LOWBIT-django-2026-25674CVE-2026-25674PYSEC-2026-2449

    Django has a Race Condition vulnerability

  • GHSA-mm6v-q8q9-pgcfLOWBIT-django-2026-7666CVE-2026-7666PYSEC-2026-200

    Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake

  • GHSA-mmwr-2jhp-mc7jLOWBIT-django-2026-4292CVE-2026-4292PYSEC-2026-53

    Django vulnerable to privilege abuse in ModelAdmin.list_editable

  • GHSA-mv8g-fhh6-6267CRITICALCVE-2016-9013PYSEC-2016-17

    Django user with hardcoded password created when running tests on Oracle

  • GHSA-mvfq-ggxm-9mc5HIGHBIT-django-2026-3902CVE-2026-3902PYSEC-2026-51

    Django vulnerable to ASGI header spoofing via underscore/hyphen conflation

  • GHSA-mwm9-4648-f68qHIGHBIT-django-2026-1207CVE-2026-1207PYSEC-2026-44

    Django has an SQL Injection issue

  • GHSA-mwv2-398h-v489MODERATECVE-2007-0405PYSEC-2026-629

    Django Improper Access Control

  • GHSA-p3fp-8748-vqfqMODERATEBIT-django-2025-26699CVE-2025-26699PYSEC-2025-13

    Django vulnerable to Allocation of Resources Without Limits or Throttling

  • GHSA-p64x-8rxx-wf6qCRITICALBIT-django-2022-34265CVE-2022-34265PYSEC-2022-213

    Django `Trunc()` and `Extract()` database functions vulnerable to SQL Injection

  • GHSA-p6m5-h7pp-v2x5HIGHCVE-2009-3695PYSEC-2009-4

    Django Regex Algorithmic Complexity Causes Denial of Service

  • GHSA-p99v-5w3c-jqq9HIGHBIT-django-2021-33571CVE-2021-33571PYSEC-2021-99

    Django Access Control Bypass possibly leading to SSRF, RFI, and LFI attacks

  • GHSA-pgxh-wfw4-jx2vMODERATECVE-2015-5963PYSEC-2015-22

    Django denial of service via empty session record creation

  • GHSA-pv4p-cwwg-4rphCRITICALBIT-django-2024-42005CVE-2024-42005PYSEC-2024-70

    Django SQL injection vulnerability

  • GHSA-pw27-w7w4-9qc7MODERATECVE-2016-2512PYSEC-2016-15

    Django XSS Vulnerability

  • GHSA-pwjp-ccjc-ghwgLOWBIT-django-2026-4277CVE-2026-4277PYSEC-2026-52

    Django vulnerable to privilege abuse in GenericInlineModelAdmin

  • GHSA-q2jf-h9jm-m7p4HIGHBIT-django-2023-23969CVE-2023-23969PYSEC-2023-12

    Django contains Uncontrolled Resource Consumption via cached header

  • GHSA-q5qw-4364-5hhmHIGHCVE-2015-5144PYSEC-2015-10

    Django Vulnerable to HTTP Response Splitting Attack

  • GHSA-q7q2-qf2q-rw3wCRITICALCVE-2014-1418PYSEC-2014-19

    Django Vulnerable to Cache Poisoning

  • GHSA-q95w-c7qg-hrffLOWBIT-django-2025-59682CVE-2025-59682PYSEC-2026-1296

    Django vulnerable to partial directory traversal via archives

  • GHSA-qc99-g3wm-hgxrHIGHCVE-2007-0404PYSEC-2026-630

    Django Arbitrary Code Execution

  • GHSA-qcgg-j2x8-h9g8MODERATEBIT-django-2024-56374CVE-2024-56374PYSEC-2025-1

    Django has a potential denial-of-service vulnerability in IPv6 validation

  • GHSA-qg2p-9jwr-mmqfHIGHBIT-django-2024-38875CVE-2024-38875PYSEC-2024-56

    Django vulnerable to Denial of Service

  • GHSA-qm57-vhq3-3fwfMODERATEBIT-django-2021-32052CVE-2021-32052PYSEC-2021-8

    Header injection possible in Django

  • GHSA-qmf9-6jqf-j8fqHIGHBIT-django-2023-46695CVE-2023-46695PYSEC-2023-222

    Django potential denial of service vulnerability in UsernameField on Windows

  • GHSA-qpc8-7fxc-cm4pLOWBIT-django-2026-35193CVE-2026-35193PYSEC-2026-197

    Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary

  • GHSA-qrh7-x6fp-c2mpMODERATECVE-2013-1664PYSEC-2026-801

    XML Entity Expansion (XEE) in Django

  • GHSA-qrw5-5h28-6cmgHIGHBIT-django-2022-41323CVE-2022-41323PYSEC-2022-304

    Django denial-of-service vulnerability in internationalized URLs

  • GHSA-qw25-v68c-qjf3HIGHBIT-django-2025-64458CVE-2025-64458PYSEC-2025-107

    Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

  • GHSA-r28v-mw67-m5p9MODERATECVE-2018-7536PYSEC-2018-5

    Django denial-of-service possibility in urlize and urlizetrunc template filters

  • GHSA-r3xc-prgr-mg9pCRITICALBIT-django-2023-31047CVE-2023-31047PYSEC-2023-61

    Django bypasses validation when using one form field to upload multiple files

  • GHSA-r5cj-wv24-92p5HIGHCVE-2008-3909PYSEC-2008-2

    Django cross-site request forgery (CSRF) vulnerability

  • GHSA-r7w6-p47g-vj53MODERATECVE-2013-0305PYSEC-2013-16

    Django Data leakage via admin history log

  • GHSA-r836-hh6v-rg5gMODERATEBIT-django-2024-41991CVE-2024-41991PYSEC-2024-69

    Django vulnerable to denial-of-service attack

  • GHSA-rf4j-j272-fj86HIGHCVE-2018-6188PYSEC-2018-4

    Django vulnerable to information leakage in AuthenticationForm

  • GHSA-rm2j-x595-q9cjHIGHCVE-2011-4139PYSEC-2011-4

    Django Vulnerable to Cache Poisoning

  • GHSA-rqw2-ghq9-44m7MODERATEBIT-django-2025-13372CVE-2025-13372PYSEC-2025-104

    Django is vulnerable to SQL injection in column aliases

  • GHSA-rrqc-c2jx-6jgvMODERATEBIT-django-2024-45231CVE-2024-45231PYSEC-2026-1297

    Django allows enumeration of user e-mail addresses

  • GHSA-rvq6-mrpv-m6rmCRITICALCVE-2014-0472PYSEC-2014-1

    Code Injection in Django

  • GHSA-rw75-m7gp-92m3MODERATECVE-2014-0483PYSEC-2014-7

    Django data leakage via querystring manipulation in admin

  • GHSA-rxjp-mfm9-w4wrHIGHBIT-django-2021-31542CVE-2021-31542PYSEC-2021-7

    Path Traversal in Django

  • GHSA-v6rh-hp5x-86rvMODERATEBIT-django-2021-44420CVE-2021-44420PYSEC-2021-439

    Potential bypass of an upstream access control based on URL paths in Django

  • GHSA-v9qg-3j8p-r63vHIGHCVE-2019-14235PYSEC-2019-14

    Uncontrolled Recursion in Django

  • GHSA-vfq6-hq5r-27r6CRITICALCVE-2019-19844PYSEC-2019-16

    Django Potential account hijack via password reset form

  • GHSA-vjjp-9r83-22rcHIGHCVE-2013-4315PYSEC-2013-20

    Django Directory Traversal via ssi template tag

  • GHSA-vm8q-m57g-pff3MODERATEBIT-django-2024-27351CVE-2024-27351PYSEC-2024-47

    Regular expression denial-of-service in Django

  • GHSA-vq3h-3q7v-9prwHIGHCVE-2014-3730PYSEC-2014-20

    Django Allows Open Redirects

  • GHSA-vrcr-9hj9-jcg6MODERATEBIT-django-2025-64460CVE-2025-64460PYSEC-2025-109

    Django is vulnerable to DoS via XML serializer text extraction

  • GHSA-w24h-v9qh-8gxjCRITICALBIT-django-2022-28347CVE-2022-28347PYSEC-2022-191

    SQL Injection in Django

  • GHSA-w26r-rmm8-9c29MODERATEBIT-django-2026-5766CVE-2026-5766PYSEC-2026-54

    Django has an Improper Handling of Length Parameter Inconsistency

  • GHSA-wh4h-v3f2-r2ppHIGHCVE-2019-6975PYSEC-2019-18

    Uncontrolled Memory Consumption in Django

  • GHSA-wpjr-j57x-wxfwHIGHBIT-django-2020-13254CVE-2020-13254PYSEC-2020-31

    Data leakage via cache key collision in Django

  • GHSA-wqfg-m96j-85vmMODERATEBIT-django-2025-27556CVE-2025-27556PYSEC-2025-14

    Django Potential Denial of Service (DoS) on Windows

  • GHSA-wqjj-hx84-v449HIGHCVE-2014-0474PYSEC-2014-3

    Django Vulnerable to MySQL Injection

  • GHSA-wxg3-mfph-qg9wHIGHCVE-2011-4138PYSEC-2011-3

    Django Might Allow CSRF Requests via URL Verification

  • GHSA-x38m-486c-2wr9MODERATECVE-2015-5964PYSEC-2015-23

    Denial-of-service possibility in logout() view by filling session store

  • GHSA-x64m-686f-fmm3MODERATECVE-2013-1665PYSEC-2026-802

    XML External Entity (XXE) in Django

  • GHSA-x7q2-wr7g-xqmfMODERATEBIT-django-2024-39329CVE-2024-39329PYSEC-2024-57

    Django vulnerable to user enumeration attack

  • GHSA-x88j-93vc-wpmpMODERATECVE-2011-4136PYSEC-2011-1

    Session manipulation in Django

  • GHSA-xgxc-v2qg-chmhMODERATEBIT-django-2021-28658CVE-2021-28658PYSEC-2021-6

    Directory Traversal in Django

  • GHSA-xpfp-f569-q3p2CRITICALBIT-django-2021-35042CVE-2021-35042PYSEC-2021-109

    SQL Injection in Django

  • GHSA-xxj9-f6rv-m3x4HIGHBIT-django-2024-24680CVE-2024-24680PYSEC-2024-28

    Django denial-of-service attack in the intcomma template filter

  • PYSEC-2007-1UNKNOWNCVE-2007-5712GHSA-9v8h-57gv-qch6

    The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows rem

  • PYSEC-2008-1UNKNOWNCVE-2008-2302GHSA-54qj-48vx-cr9f

    Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject

  • PYSEC-2008-2UNKNOWNCVE-2008-3909GHSA-r5cj-wv24-92p5

    The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to cond

  • PYSEC-2009-3UNKNOWNCVE-2009-2659GHSA-9xg7-gg9m-rmq9

    The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory trave

  • PYSEC-2009-4UNKNOWNCVE-2009-3695GHSA-p6m5-h7pp-v2x5

    Algorithmic complexity vulnerability in the forms library in Django 1.0 before 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a crafted (1) Email

  • PYSEC-2010-12UNKNOWNCVE-2010-3082GHSA-fxpg-gg9g-76gj

    Cross-site scripting (XSS) vulnerability in Django 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via a csrfmiddlewaretoken (aka csrf_token) cookie.

  • PYSEC-2011-1UNKNOWNCVE-2011-4136GHSA-x88j-93vc-wpmp

    django.contrib.sessions in Django before 1.2.7 and 1.3.x before 1.3.1, when session data is stored in the cache, uses the root namespace for both session identifiers and application-data keys, which a

  • PYSEC-2011-10UNKNOWNCVE-2011-0696GHSA-5j2h-h5hg-3wf8

    Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site requ

  • PYSEC-2011-11UNKNOWNCVE-2011-0697GHSA-8m3r-rv5g-fcpq

    Cross-site scripting (XSS) vulnerability in Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 might allow remote attackers to inject arbitrary web script or HTML via a filename associated with a file u

  • PYSEC-2011-12UNKNOWNCVE-2011-0698GHSA-7g9h-c88w-r7h2

    Directory traversal vulnerability in Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 on Windows might allow remote attackers to read or execute files via a / (slash) character in a key in a session c

  • PYSEC-2011-2UNKNOWNCVE-2011-4137GHSA-3jqw-crqj-w8qw

    The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 relies on Python libraries that attempt access to an arbitrary URL with no timeout, which a

  • PYSEC-2011-3UNKNOWNCVE-2011-4138GHSA-wxg3-mfph-qg9w

    The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 originally tests a URL's validity through a HEAD request, but then uses a GET request for t

  • PYSEC-2011-4UNKNOWNCVE-2011-4139GHSA-rm2j-x595-q9cj

    Django before 1.2.7 and 1.3.x before 1.3.1 uses a request's HTTP Host header to construct a full URL in certain circumstances, which allows remote attackers to conduct cache poisoning attacks via a cr

  • PYSEC-2011-5UNKNOWNCVE-2011-4140GHSA-h95j-h2rv-qrg4

    The CSRF protection mechanism in Django through 1.2.7 and 1.3.x through 1.3.1 does not properly handle web-server configurations supporting arbitrary HTTP Host headers, which allows remote attackers t

  • PYSEC-2011-8UNKNOWNCVE-2010-4534GHSA-fwr5-q9rx-294f

    The administrative interface in django.contrib.admin in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not properly restrict use of the query string to perform certain objec

  • PYSEC-2011-9UNKNOWNCVE-2010-4535GHSA-7wph-fc4w-wqp2

    The password reset functionality in django.contrib.auth in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not validate the length of a string representing a base36 timestamp

  • PYSEC-2012-2UNKNOWNCVE-2012-3442GHSA-78vx-ggch-wghm

    The (1) django.http.HttpResponseRedirect and (2) django.http.HttpResponsePermanentRedirect classes in Django before 1.3.2 and 1.4.x before 1.4.1 do not validate the scheme of a redirect target, which

  • PYSEC-2012-3UNKNOWNCVE-2012-3443GHSA-59w8-4wm2-4xw8

    The django.forms.ImageField class in the form system in Django before 1.3.2 and 1.4.x before 1.4.1 completely decompresses image data during image validation, which allows remote attackers to cause a

  • PYSEC-2012-4UNKNOWNCVE-2012-3444GHSA-5h2q-4hrp-v9rr

    The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows rem

  • PYSEC-2012-7UNKNOWNCVE-2012-4520GHSA-2655-q453-22f9

    The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host

  • PYSEC-2013-16UNKNOWNCVE-2013-0305GHSA-r7w6-p47g-vj53

    The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated ad

  • PYSEC-2013-17UNKNOWNCVE-2013-0306GHSA-g8xg-jgj6-49r3

    The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of serv

  • PYSEC-2013-18UNKNOWNCVE-2013-1443GHSA-4c42-4rxm-x6qf

    The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption)

  • PYSEC-2013-19UNKNOWNCVE-2013-4249GHSA-4894-5vqc-6r2r

    Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget in contrib/admin/widgets.py in Django 1.5.x before 1.5.2 and 1.6.x before 1.6 beta 2 allows remote attackers to inject arbitr

  • PYSEC-2013-20UNKNOWNCVE-2013-4315GHSA-vjjp-9r83-22rc

    Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x before 1.5.3, and 1.6.x before 1.6 beta 3 allows remote attackers to read arbitrary files via a file path in the ALLOWED_INCLUDE_R

  • PYSEC-2013-21UNKNOWNCVE-2013-6044GHSA-9cwg-mhxf-hh59

    The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL's scheme as safe even if it is not HTTP or HTTPS, which might introduce c

  • PYSEC-2014-1UNKNOWNCVE-2014-0472GHSA-rvq6-mrpv-m6rm

    The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Pytho

  • PYSEC-2014-19UNKNOWNCVE-2014-1418GHSA-q7q2-qf2q-rw3w

    Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attacker

  • PYSEC-2014-2UNKNOWNCVE-2014-0473GHSA-89hj-xfx5-7q66

    The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to

  • PYSEC-2014-20UNKNOWNCVE-2014-3730GHSA-vq3h-3q7v-9prw

    The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduc

  • PYSEC-2014-3UNKNOWNCVE-2014-0474GHSA-wqjj-hx84-v449

    The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properl

  • PYSEC-2014-4UNKNOWNCVE-2014-0480GHSA-f7cm-ccfp-3q4r

    The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attacker

  • PYSEC-2014-5UNKNOWNCVE-2014-0481GHSA-296w-6qhq-gf92

    The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation

  • PYSEC-2014-6UNKNOWNCVE-2014-0482GHSA-625g-gx8c-xcmg

    The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.Re

  • PYSEC-2014-7UNKNOWNCVE-2014-0483GHSA-rw75-m7gp-92m3

    The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship bet

  • PYSEC-2015-10UNKNOWNCVE-2015-5144GHSA-q5qw-4364-5hhm

    Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorrect regular expression, which allows remote attackers to inject arbitrary headers and conduct HTTP r

  • PYSEC-2015-11UNKNOWNCVE-2015-8213GHSA-6wcr-wcqm-3mfh

    The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a

  • PYSEC-2015-18UNKNOWNCVE-2015-2316GHSA-j3j3-jrfh-cm2w

    The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of servic

  • PYSEC-2015-19UNKNOWNCVE-2015-3982GHSA-6wgp-fwfm-mxp3

    The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the s

  • PYSEC-2015-20UNKNOWNCVE-2015-5143GHSA-h582-2pch-3xv3

    The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (session store consumption) via multi

  • PYSEC-2015-21UNKNOWNCVE-2015-5145GHSA-cqf7-ff9h-7967

    validators.URLValidator in Django 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.

  • PYSEC-2015-22UNKNOWNCVE-2015-5963GHSA-pgxh-wfw4-jx2v

    contrib.sessions.middleware.SessionMiddleware in Django 1.8.x before 1.8.4, 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions allows remote attackers to cause a denial of service (

  • PYSEC-2015-23UNKNOWNCVE-2015-5964GHSA-x38m-486c-2wr9

    The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sess

  • PYSEC-2015-4UNKNOWNCVE-2015-0219GHSA-7qfw-j7hp-v45g

    Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header,

  • PYSEC-2015-5UNKNOWNCVE-2015-0220GHSA-gv98-g628-m9x5

    The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cr

  • PYSEC-2015-6UNKNOWNCVE-2015-0221GHSA-jhjg-w2cp-5j44

    The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service

  • PYSEC-2015-7UNKNOWNCVE-2015-0222GHSA-6g95-x6cj-mg4v

    ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate val

  • PYSEC-2015-8UNKNOWNCVE-2015-2241GHSA-6565-fg86-6jcx

    Cross-site scripting (XSS) vulnerability in the contents function in admin/helpers.py in Django before 1.7.6 and 1.8 before 1.8b2 allows remote attackers to inject arbitrary web script or HTML via a m

  • PYSEC-2015-9UNKNOWNCVE-2015-2317GHSA-7fq8-4pv5-5w5c

    The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to co

  • PYSEC-2016-14UNKNOWNCVE-2016-2048GHSA-46x4-9jmv-jc8p

    Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option w

  • PYSEC-2016-15UNKNOWNCVE-2016-2512GHSA-pw27-w7w4-9qc7

    The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cro

  • PYSEC-2016-16UNKNOWNCVE-2016-2513GHSA-fp6p-5xvw-m74f

    The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.

  • PYSEC-2016-17UNKNOWNCVE-2016-9013GHSA-mv8g-fhh6-6267

    Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easi

  • PYSEC-2016-18UNKNOWNCVE-2016-9014GHSA-3f2c-jm6v-cr35

    Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate

  • PYSEC-2016-2UNKNOWNCVE-2016-6186GHSA-c8c8-9472-w52h

    Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and

  • PYSEC-2016-3UNKNOWNCVE-2016-7401GHSA-crhm-qpjc-cm64

    The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting a

  • PYSEC-2017-10UNKNOWNCVE-2017-7234GHSA-h4hv-m4h4-mhwg

    A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open

  • PYSEC-2017-44UNKNOWNCVE-2017-12794GHSA-9r8w-6x8c-6jr9

    In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for the technical 500 debug page. Given the right circumstances, this allowed a cro

  • PYSEC-2017-9UNKNOWNCVE-2017-7233GHSA-37hp-765x-j95x

    Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``dja

  • PYSEC-2018-2UNKNOWNCVE-2018-14574GHSA-5hg3-6c2f-f3wr

    django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.

  • PYSEC-2018-3UNKNOWNCVE-2018-16984GHSA-6mx3-3vqg-hpp2

    An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an

  • PYSEC-2018-4UNKNOWNCVE-2018-6188GHSA-rf4j-j272-fj86

    django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the

  • PYSEC-2018-5UNKNOWNCVE-2018-7536GHSA-r28v-mw67-m5p9

    An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastrophi

  • PYSEC-2018-6UNKNOWNCVE-2018-7537GHSA-2f9x-5v75-3qv4

    An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they we

  • PYSEC-2019-10UNKNOWNCVE-2019-12781GHSA-6c7v-2f49-8h26

    An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT sett

  • PYSEC-2019-11UNKNOWNCVE-2019-14232GHSA-c4qh-4vgv-qc6g

    An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, t

  • PYSEC-2019-12UNKNOWNCVE-2019-14233GHSA-h5jv-4p7w-64jg

    An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behaviour of the underlying HTMLParser, django.utils.html.strip_tags would be extremely

  • PYSEC-2019-13UNKNOWNCVE-2019-14234GHSA-6r97-cj55-9hrq

    An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.f

  • PYSEC-2019-14UNKNOWNCVE-2019-14235GHSA-v9qg-3j8p-r63v

    An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding.uri_to_iri could lead to significant memory usage

  • PYSEC-2019-15UNKNOWNCVE-2019-19118GHSA-hvmf-r92r-27hr

    Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but edi

  • PYSEC-2019-16UNKNOWNCVE-2019-19844GHSA-vfq6-hq5r-27r6

    Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of

  • PYSEC-2019-17UNKNOWNCVE-2019-3498GHSA-337x-4q8g-prc5

    In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defau

  • PYSEC-2019-18UNKNOWNCVE-2019-6975GHSA-wh4h-v3f2-r2pp

    Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() funct

  • PYSEC-2019-79UNKNOWNCVE-2019-12308GHSA-7rp2-fm2h-wchj

    An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the provided value without

  • PYSEC-2020-31UNKNOWNBIT-django-2020-13254CVE-2020-13254GHSA-wpjr-j57x-wxfw

    An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collisi

  • PYSEC-2020-32UNKNOWNBIT-django-2020-13596CVE-2020-13596GHSA-2m34-jcjv-45xf

    An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility o

  • PYSEC-2020-33UNKNOWNBIT-django-2020-24583CVE-2020-24583GHSA-m6gj-h9gm-gw44

    An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level di

  • PYSEC-2020-34UNKNOWNBIT-django-2020-24584CVE-2020-24584GHSA-fr28-569j-53c4

    An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's sta

  • PYSEC-2020-35UNKNOWNBIT-django-2020-7471CVE-2020-7471GHSA-hmr4-m2h5-33qx

    Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data a

  • PYSEC-2020-36UNKNOWNBIT-django-2020-9402CVE-2020-9402GHSA-3gh2-xw74-jmcw

    Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suit

  • PYSEC-2021-109UNKNOWNBIT-django-2021-35042CVE-2021-35042GHSA-xpfp-f569-q3p2

    Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.

  • PYSEC-2021-439UNKNOWNBIT-django-2021-44420CVE-2021-44420GHSA-v6rh-hp5x-86rv

    In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

  • PYSEC-2021-6UNKNOWNBIT-django-2021-28658CVE-2021-28658GHSA-xgxc-v2qg-chmh

    In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not

  • PYSEC-2021-7UNKNOWNBIT-django-2021-31542CVE-2021-31542GHSA-rxjp-mfm9-w4wr

    In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.

  • PYSEC-2021-8UNKNOWNBIT-django-2021-32052CVE-2021-32052GHSA-qm57-vhq3-3fwf

    In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application

  • PYSEC-2021-9UNKNOWNBIT-django-2021-3281CVE-2021-3281GHSA-fvgf-6h6h-3322

    In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal v

  • PYSEC-2021-98UNKNOWNBIT-django-2021-33203CVE-2021-33203GHSA-68w8-qjq3-2gfm

    Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the exist

  • PYSEC-2021-99UNKNOWNBIT-django-2021-33571CVE-2021-33571GHSA-p99v-5w3c-jqq9

    In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This ma

  • PYSEC-2022-1UNKNOWNBIT-django-2021-45115CVE-2021-45115GHSA-53qw-q765-4fww

    An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. UserAttributeSimilarityValidator incurred significant overhead in evaluating a submitted password that was

  • PYSEC-2022-19UNKNOWNBIT-django-2022-22818CVE-2022-22818GHSA-95rw-fx8r-36v6

    The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.

  • PYSEC-2022-190UNKNOWNBIT-django-2022-28346CVE-2022-28346GHSA-2gwj-7jmv-h26r

    An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a

  • PYSEC-2022-191UNKNOWNBIT-django-2022-28347CVE-2022-28347GHSA-w24h-v9qh-8gxj

    A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion)

  • PYSEC-2022-2UNKNOWNBIT-django-2021-45116CVE-2021-45116GHSA-8c5j-9r9f-c6w8

    An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variable resolution logic, the dictsort template filter w

  • PYSEC-2022-20UNKNOWNBIT-django-2022-23833CVE-2022-23833GHSA-6cw3-g6wv-c2xv

    An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing

  • PYSEC-2022-213UNKNOWNBIT-django-2022-34265CVE-2022-34265GHSA-p64x-8rxx-wf6q

    An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name valu

  • PYSEC-2022-245UNKNOWNBIT-django-2022-36359CVE-2022-36359GHSA-8x94-hmjh-97hq

    An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Di

  • PYSEC-2022-3UNKNOWNBIT-django-2021-45452CVE-2021-45452GHSA-jrh2-hc4r-7jwx

    Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed to it.

  • PYSEC-2022-304UNKNOWNBIT-django-2022-41323CVE-2022-41323GHSA-qrw5-5h28-6cmg

    In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular

  • PYSEC-2023-100UNKNOWNBIT-django-2023-36053CVE-2023-36053GHSA-jh3w-4vvf-mjgr

    In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large numb

  • PYSEC-2023-12UNKNOWNBIT-django-2023-23969CVE-2023-23969GHSA-q2jf-h9jm-m7p4

    In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-s

  • PYSEC-2023-13UNKNOWNBIT-django-2023-24580CVE-2023-24580GHSA-2hrw-hx67-34x6

    An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart f

  • PYSEC-2023-222UNKNOWNBIT-django-2023-46695CVE-2023-46695GHSA-qmf9-6jqf-j8fq

    An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.forms.UsernameField is su

  • PYSEC-2023-225UNKNOWNBIT-django-2023-41164CVE-2023-41164GHSA-7h4p-27mh-hmrw

    In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large n

  • PYSEC-2023-226UNKNOWNBIT-django-2023-43665CVE-2023-43665GHSA-h8gc-pgj2-vjm3

    In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of s

  • PYSEC-2023-61UNKNOWNBIT-django-2023-31047CVE-2023-31047GHSA-r3xc-prgr-mg9p

    In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been suppor

  • PYSEC-2024-102UNKNOWNBIT-django-2024-45230CVE-2024-45230GHSA-5hgc-2vfp-mqvc

    An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via ver

  • PYSEC-2024-156UNKNOWNBIT-django-2024-53907CVE-2024-53907GHSA-8498-2h75-472j

    An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack

  • PYSEC-2024-157UNKNOWNBIT-django-2024-53908CVE-2024-53908GHSA-m9g8-fxxm-xg86

    An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subjec

  • PYSEC-2024-28UNKNOWNBIT-django-2024-24680CVE-2024-24680GHSA-xxj9-f6rv-m3x4

    An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with ver

  • PYSEC-2024-47UNKNOWNBIT-django-2024-27351CVE-2024-27351GHSA-vm8q-m57g-pff3

    In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a potent

  • PYSEC-2024-56UNKNOWNBIT-django-2024-38875CVE-2024-38875GHSA-qg2p-9jwr-mmqf

    An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack via certain inputs with a very large number of bra

  • PYSEC-2024-57UNKNOWNBIT-django-2024-39329CVE-2024-39329GHSA-x7q2-wr7g-xqmf

    An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.authenticate() method allows remote attackers to enumerate users via a timing at

  • PYSEC-2024-58UNKNOWNBIT-django-2024-39330CVE-2024-39330GHSA-9jmf-237g-qf46

    An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.storage.Storage base class, when they override generate_filename() without replicatin

  • PYSEC-2024-59UNKNOWNBIT-django-2024-39614CVE-2024-39614GHSA-f6f8-9mx6-9mx2

    An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings containi

  • PYSEC-2024-67UNKNOWNBIT-django-2024-41989CVE-2024-41989GHSA-jh75-99hh-qvx9

    An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given a string representation of a number in

  • PYSEC-2024-68UNKNOWNBIT-django-2024-41990CVE-2024-41990GHSA-795c-9xpc-xw6g

    An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with

  • PYSEC-2024-69UNKNOWNBIT-django-2024-41991CVE-2024-41991GHSA-r836-hh6v-rg5g

    An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service

  • PYSEC-2024-70UNKNOWNBIT-django-2024-42005CVE-2024-42005GHSA-pv4p-cwwg-4rph

    An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a cr

  • PYSEC-2025-1UNKNOWNBIT-django-2024-56374CVE-2024-56374GHSA-qcgg-j2x8-h9g8

    An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a po

  • PYSEC-2025-104LOWBIT-django-2025-13372CVE-2025-13372GHSA-rqw2-ghq9-44m7

    An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27.

  • PYSEC-2025-105LOWBIT-django-2025-57833CVE-2025-57833GHSA-6w2r-r2m5-xq5w

    An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with

  • PYSEC-2025-106LOWBIT-django-2025-59681CVE-2025-59681GHSA-hpr9-3m2g-3j9p

    An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injec

  • PYSEC-2025-107LOWBIT-django-2025-64458CVE-2025-64458GHSA-qw25-v68c-qjf3

    An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.

  • PYSEC-2025-108LOWBIT-django-2025-64459CVE-2025-64459GHSA-frmv-pr5f-9mcr

    An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.

  • PYSEC-2025-109LOWBIT-django-2025-64460CVE-2025-64460GHSA-vrcr-9hj9-jcg6

    An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27.

  • PYSEC-2025-13UNKNOWNBIT-django-2025-26699CVE-2025-26699GHSA-p3fp-8748-vqfq

    An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-serv

  • PYSEC-2025-14UNKNOWNBIT-django-2025-27556CVE-2025-27556GHSA-wqfg-m96j-85vm

    An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.Lo

  • PYSEC-2025-37UNKNOWNBIT-django-2025-32873CVE-2025-32873GHSA-8j24-cjrq-gr2m

    An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performanc

  • PYSEC-2025-47UNKNOWNBIT-django-2025-48432CVE-2025-48432GHSA-7xr5-9hcq-chf9

    An issue was discovered in Django 5.2 before 5.2.2, 5.1 before 5.1.10, and 4.2 before 4.2.22. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially

  • PYSEC-2026-1296LOWBIT-django-2025-59682CVE-2025-59682GHSA-q95w-c7qg-hrff

    Django vulnerable to partial directory traversal via archives

  • PYSEC-2026-1297LOWBIT-django-2024-45231CVE-2024-45231GHSA-rrqc-c2jx-6jgv

    Django allows enumeration of user e-mail addresses

  • PYSEC-2026-197MEDIUMBIT-django-2026-35193CVE-2026-35193GHSA-qpc8-7fxc-cm4p

    An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.

  • PYSEC-2026-198LOWBIT-django-2026-48587CVE-2026-48587GHSA-923m-gv2p-w5qp

    An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.

  • PYSEC-2026-199LOWBIT-django-2026-6873CVE-2026-6873GHSA-h7pc-vwp9-298g

    An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15.

  • PYSEC-2026-200MEDIUMBIT-django-2026-7666CVE-2026-7666GHSA-mm6v-q8q9-pgcf

    An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15.

  • PYSEC-2026-201LOWBIT-django-2026-8404CVE-2026-8404GHSA-8cjm-8mp7-r2xf

    An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.

  • PYSEC-2026-2090LOWBIT-django-2026-48588CVE-2026-48588GHSA-3h9f-r86x-qvjx

    An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.

  • PYSEC-2026-2091MEDIUMBIT-django-2026-53877CVE-2026-53877GHSA-crhf-3pfg-w68w

    An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.

  • PYSEC-2026-2092MEDIUMBIT-django-2026-53878CVE-2026-53878GHSA-8qcx-xf44-272x

    An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.

  • PYSEC-2026-2448LOWBIT-django-2026-25673CVE-2026-25673GHSA-8p8v-wh79-9r56

    Django vulnerable to Uncontrolled Resource Consumption

  • PYSEC-2026-2449LOWBIT-django-2026-25674CVE-2026-25674GHSA-mjgh-79qc-68w3

    Django has a Race Condition vulnerability

  • PYSEC-2026-3717MEDIUMBIT-django-2026-15830CVE-2026-15830

    An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.

  • PYSEC-2026-42LOWBIT-django-2025-13473CVE-2025-13473GHSA-2mcm-79hx-8fxw

    An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.

  • PYSEC-2026-43LOWBIT-django-2025-14550CVE-2025-14550GHSA-33mw-q7rj-mjwj

    An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.

  • PYSEC-2026-44LOWBIT-django-2026-1207CVE-2026-1207GHSA-mwm9-4648-f68q

    An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.

  • PYSEC-2026-45LOWBIT-django-2026-1285CVE-2026-1285GHSA-4rrr-2h4v-f3j9

    An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.

  • PYSEC-2026-46LOWBIT-django-2026-1287CVE-2026-1287GHSA-gvg8-93h5-g6qq

    An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.

  • PYSEC-2026-47LOWBIT-django-2026-1312CVE-2026-1312GHSA-6426-9fv3-65x8

    An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.

  • PYSEC-2026-48LOWBIT-django-2026-33033CVE-2026-33033GHSA-5mf9-h53q-7mhq

    An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.

  • PYSEC-2026-49LOWBIT-django-2026-33034CVE-2026-33034GHSA-933h-hp56-hf7m

    An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.

  • PYSEC-2026-50LOWBIT-django-2026-35192CVE-2026-35192GHSA-7h2m-m8vj-598h

    An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.

  • PYSEC-2026-51LOWBIT-django-2026-3902CVE-2026-3902GHSA-mvfq-ggxm-9mc5

    An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.

  • PYSEC-2026-52LOWBIT-django-2026-4277CVE-2026-4277GHSA-pwjp-ccjc-ghwg

    An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.

  • PYSEC-2026-53LOWBIT-django-2026-4292CVE-2026-4292GHSA-mmwr-2jhp-mc7j

    An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.

  • PYSEC-2026-54MEDIUMBIT-django-2026-5766CVE-2026-5766GHSA-w26r-rmm8-9c29

    An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.

  • PYSEC-2026-55LOWBIT-django-2026-6907CVE-2026-6907GHSA-5hrc-gvxj-w55p

    An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.

  • PYSEC-2026-628LOWCVE-2019-11358DRUPAL-CORE-2019-006GHSA-6c3j-c64m-qhgq

    XSS in jQuery as used in Drupal, Backdrop CMS, and other products

  • PYSEC-2026-629UNKNOWNCVE-2007-0405GHSA-mwv2-398h-v489

    Django Improper Access Control

  • PYSEC-2026-630UNKNOWNCVE-2007-0404GHSA-qc99-g3wm-hgxr

    Django Arbitrary Code Execution

  • PYSEC-2026-801UNKNOWNCVE-2013-1664GHSA-qrh7-x6fp-c2mp

    XML Entity Expansion (XEE) in Django

  • PYSEC-2026-802UNKNOWNCVE-2013-1665GHSA-x64m-686f-fmm3

    XML External Entity (XXE) in Django

Key facts

Latest version
v6.1.1
Last release
2 September 2026 (5 days ago)
Total releases
433
First release
17 May 2010
Package age
16.3 years
Maintainers
not exposed by PyPI
Known advisories
321
Confidence
High

Frequently asked

Is Django still maintained?

Yes — Django released as recently as 2 September 2026 (5 days ago), so it is actively maintained.

Does Django have known security vulnerabilities?

Yes — OSV lists 321 advisories for Django, including 16 rated critical. See the advisory list on this page for the OSV/GHSA identifiers.

Is Django safe to use?

No — Django carries 16 unpatched critical advisories and should not be adopted without a remediation plan. OSPulse rates it 55/100 (medium risk) based on release recency, cadence and known vulnerabilities.

Alternatives to django

Other PyPI packages we've checked

Browse all checked packages →

django is one package. What about the other hundreds in your tree?

Paste your own requirements.txt into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.

Data from the PyPI registry & OSV.dev · snapshot generated 2026-09-07 · scores are deterministic and recomputed on each refresh.