---
id: CVE-2026-16216
title: A weakness has been identified in geex-arts django-jet up to 1.0.8
summary: >-
  A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected
  is an unknown function of the component OAuth Handler. Executing a
  manipulation can lead to cross-site request forgery. The attack may be
  performed from remote.…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-352
  - CWE-862
published: '2026-07-19'
updated: '2026-07-19'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16216'
references:
  - url: 'https://github.com/geex-arts/django-jet/'
    label: cna@vuldb.com
  - url: 'https://github.com/geex-arts/django-jet/issues/528'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-16216'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/857947'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/380039'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/380039/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.0023
epssPercentile: 0.12272
ingestedAt: '2026-07-19T14:31:06.913Z'
---

## Overview

A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAuth Handler. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
