---
id: CVE-2024-25170
aliases:
  - GHSA-22cc-w7xm-rfhx
  - PYSEC-2026-1626
title: >-
  Mezzanine allows attackers to bypass access controls via manipulating the Host
  header
summary: >-
  Mezzanine allows attackers to bypass access controls via manipulating the Host
  header
severity: medium
vendor: mezzanine
product: mezzanine
ecosystem: pip
affected:
  - mezzanine <= 6.0.0
published: '2024-02-28'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-22cc-w7xm-rfhx'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-25170'
  - url: 'https://github.com/shenhav12/CVE-2024-25170-Mezzanine-v6.0.0'
  - url: 'https://github.com/stephenmcd/mezzanine'
  - url: 'https://ibb.co/DpxHpz9'
  - url: 'https://ibb.co/T0fhLwR'
tags:
  - osv
  - pip
  - exploit-available
epss: 0.00881
epssPercentile: 0.57421
ingestedAt: '2026-07-08T18:25:44.113Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/shenhav12/CVE-2024-25170-Mezzanine-v6.0.0'
  checkedAt: '2026-09-26T09:05:31.001Z'
exploitAvailable: true
---

## Overview

An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.

## Affected packages

- `mezzanine <= 6.0.0`

## Remediation

Refer to the advisory for the patched release.
