CVE-2026-87975
- EPSS 0.24%
- Veröffentlicht 06.10.2026 13:35:59
- Zuletzt bearbeitet 06.10.2026 14:17:47
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.forms.models.BaseModelFormSet.save_existing_objects()` used the presence of a primary key on a submitted form's instance as evidence that the instanc...
CVE-2026-87890
- EPSS 0.29%
- Veröffentlicht 06.10.2026 13:35:37
- Zuletzt bearbeitet 06.10.2026 14:17:47
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply `bytes` values to cause the Django process to make network r...
CVE-2026-84429
- EPSS 0.38%
- Veröffentlicht 06.10.2026 13:35:17
- Zuletzt bearbeitet 06.10.2026 15:17:19
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.http.parse_header_parameters()` was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with ...
CVE-2026-77050
- EPSS 0.38%
- Veröffentlicht 06.10.2026 13:34:40
- Zuletzt bearbeitet 06.10.2026 15:17:19
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.translation.get_supported_language_variant()` is subject to a potential denial-of-service attack when processing many distinct, very long lan...
CVE-2026-15920
- EPSS 0.3%
- Veröffentlicht 04.08.2026 15:48:40
- Zuletzt bearbeitet 17.08.2026 19:17:54
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is d...
CVE-2026-15830
- EPSS 0.52%
- Veröffentlicht 04.08.2026 15:48:34
- Zuletzt bearbeitet 08.10.2026 11:16:46
An issue was discovered in Django 6.0 before 6.0.9 and 5.2 before 5.2.18. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known te...
CVE-2026-15337
- EPSS 0.52%
- Veröffentlicht 04.08.2026 15:48:25
- Zuletzt bearbeitet 18.08.2026 16:30:12
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as key...
CVE-2026-15307
- EPSS 0.54%
- Veröffentlicht 04.08.2026 15:48:18
- Zuletzt bearbeitet 18.08.2026 16:29:03
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a ...
CVE-2026-53878
- EPSS 0.21%
- Veröffentlicht 07.07.2026 14:10:29
- Zuletzt bearbeitet 09.07.2026 12:58:17
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines ...
CVE-2026-53877
- EPSS 0.28%
- Veröffentlicht 07.07.2026 14:10:04
- Zuletzt bearbeitet 09.07.2026 12:59:39
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a...