Djangoproject

Django

161 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 06.10.2026 13:35:59
  • Zuletzt bearbeitet 06.10.2026 14:17:47

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.forms.models.BaseModelFormSet.save_existing_objects()` used the presence of a primary key on a submitted form's instance as evidence that the instanc...

  • EPSS 0.29%
  • Veröffentlicht 06.10.2026 13:35:37
  • Zuletzt bearbeitet 06.10.2026 14:17:47

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply `bytes` values to cause the Django process to make network r...

  • EPSS 0.38%
  • Veröffentlicht 06.10.2026 13:35:17
  • Zuletzt bearbeitet 06.10.2026 15:17:19

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.http.parse_header_parameters()` was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with ...

  • EPSS 0.38%
  • Veröffentlicht 06.10.2026 13:34:40
  • Zuletzt bearbeitet 06.10.2026 15:17:19

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.translation.get_supported_language_variant()` is subject to a potential denial-of-service attack when processing many distinct, very long lan...

Medienbericht
  • EPSS 0.3%
  • Veröffentlicht 04.08.2026 15:48:40
  • Zuletzt bearbeitet 17.08.2026 19:17:54

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is d...

Medienbericht
  • EPSS 0.52%
  • Veröffentlicht 04.08.2026 15:48:34
  • Zuletzt bearbeitet 08.10.2026 11:16:46

An issue was discovered in Django 6.0 before 6.0.9 and 5.2 before 5.2.18. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known te...

Medienbericht
  • EPSS 0.52%
  • Veröffentlicht 04.08.2026 15:48:25
  • Zuletzt bearbeitet 18.08.2026 16:30:12

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as key...

Medienbericht
  • EPSS 0.54%
  • Veröffentlicht 04.08.2026 15:48:18
  • Zuletzt bearbeitet 18.08.2026 16:29:03

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a ...

  • EPSS 0.21%
  • Veröffentlicht 07.07.2026 14:10:29
  • Zuletzt bearbeitet 09.07.2026 12:58:17

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines ...

  • EPSS 0.28%
  • Veröffentlicht 07.07.2026 14:10:04
  • Zuletzt bearbeitet 09.07.2026 12:59:39

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a...