{"id":"CVE-2024-25170","aliases":["GHSA-22cc-w7xm-rfhx","PYSEC-2026-1626"],"title":"Mezzanine allows attackers to bypass access controls via manipulating the Host header","summary":"Mezzanine allows attackers to bypass access controls via manipulating the Host header","severity":"medium","vendor":"mezzanine","product":"mezzanine","ecosystem":"pip","affected":["mezzanine <= 6.0.0"],"published":"2024-02-28","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-22cc-w7xm-rfhx","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-25170"},{"url":"https://github.com/shenhav12/CVE-2024-25170-Mezzanine-v6.0.0"},{"url":"https://github.com/stephenmcd/mezzanine"},{"url":"https://ibb.co/DpxHpz9"},{"url":"https://ibb.co/T0fhLwR"}],"tags":["osv","pip","exploit-available"],"epss":0.00881,"epssPercentile":0.57605,"ingestedAt":"2026-07-08T18:25:44.113Z","exploits":{"github":1,"githubRepos":["https://github.com/shenhav12/CVE-2024-25170-Mezzanine-v6.0.0"],"checkedAt":"2026-09-23T07:13:28.783Z"},"exploitAvailable":true,"slug":"CVE-2024-25170","body":"## Overview\n\nAn issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.\n\n## Affected packages\n\n- `mezzanine <= 6.0.0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":27.5,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":4703,"id":"CVE-2024-25170","ts":1788887200280,"field":"exploit_available","old":"false","new":"true"},{"seq":3586,"id":"CVE-2024-25170","ts":1788886316772,"field":"exploit_available","old":"true","new":"false"},{"seq":2440,"id":"CVE-2024-25170","ts":1788882985513,"field":"exploit_available","old":"false","new":"true"},{"seq":1469,"id":"CVE-2024-25170","ts":1788882398805,"field":"exploit_available","old":"true","new":"false"},{"seq":583,"id":"CVE-2024-25170","ts":1788881835444,"field":"exploit_available","old":"false","new":"true"}]}