CVE-2025-59682High· 8.8▾ TwilightA flaw was found in Django. The django.utils.archive.extract() function, used by startapp --templateand startproject --template, allowed partial directory-traversal via an archive with file paths sharing a common prefix with the target dir…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.9%
0.9% → 0.9%
Last analysed / modified upstream
3.1 → 8.8
low → high
A flaw was found in Django. The django.utils.archive.extract() function, used by startapp --templateand startproject --template, allowed partial directory-traversal via an archive with file paths sharing a common prefix with the target directory.
django: Potential partial directory-traversal via archive.extract() — rated Important by Red Hat. Released 2025-10-01, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
Red Hat Ansible Automation Platform https://access.redhat.com/errata/RHSA-2025:18979 Red Hat Ansible Automation Platform https://access.redhat.com/errata/RHSA-2025:18984 Red Hat Ansible Automation Platform https://access.redhat.com/errata/RHSA-2025:19201
Workarounds / mitigations:
Affected packages:
django >= 4.2, < 4.2.25django >= 5.1, < 5.1.13django >= 5.2, < 5.2.7Patched in:
django 4.2.25django 5.1.13django 5.2.7Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-39373High· 7.5JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens (CVE-2026-39373)
CVE-2026-15801High· 8.0A vulnerability was found in CRI-O related to the container checkpoint and restore feature
CVE-2023-27534Low· 3.7curl: SFTP path ~ resolving discrepancy (CVE-2023-27534)
CVE-2026-81829Medium· 5.3A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers
CVE-2026-79705Medium· 4.5A flaw was found in the buildah/copier Go package
CVE-2025-6020High· 7.8A flaw was found in linux-pam