Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-15830NoneAn issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as …
CVE-2026-53878Medium· 6.1Django: DomainNameValidator permits newline characters that may enable HTTP header injection
CVE-2026-53877Medium· 4.8Django: GDALRaster may over-read heap memory when constructed from bytes
CVE-2026-48588Low· 3.1Django: cache middleware may expose private responses when unrelated request cookies are present
CVE-2026-35193Low· 3.1Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary
CVE-2026-6873Low· 3.1Django: signed cookies are vulnerable to salt namespace collisions
CVE-2026-48587Low· 3.1Django: has_vary_header may expose cached responses when Vary values contain whitespace
CVE-2026-8404Low· 3.1Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
CVE-2026-7666Low· 3.1Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
CVE-2026-5766Medium· 5.3Django has an Improper Handling of Length Parameter Inconsistency
CVE-2026-6907Medium· 4.3Django Uses Cache Containing Sensitive Information
CVE-2026-4292Low· 2.7Django vulnerable to privilege abuse in ModelAdmin.list_editable
CVE-2026-33034High· 7.5Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit
CVE-2026-33033Medium· 6.5PoCDjango has potential DoS via MultiPartParser through crafted multipart uploads
CVE-2026-25674Low· 3.7Django has a Race Condition vulnerability
CVE-2026-25673High· 7.5Django vulnerable to Uncontrolled Resource Consumption
CVE-2026-1285LowDjango has Inefficient Algorithmic Complexity
CVE-2025-14550LowDjango has Inefficient Algorithmic Complexity
CVE-2025-13473LowDjango has Observable Timing Discrepancy
CVE-2025-64460MediumDjango is vulnerable to DoS via XML serializer text extraction
CVE-2025-13372Medium· 4.3Django is vulnerable to SQL injection in column aliases
CVE-2025-64458High· 7.5PoCDjango has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2025-57833High· 7.1PoCDjango is subject to SQL injection through its column aliases
CVE-2025-48432Medium· 4.0Django Improper Output Neutralization for Logs vulnerability
CVE-2025-32873Medium· 5.3PoCDjango has a denial-of-service possibility in strip_tags()
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.