CVE-2026-7666Low· 3.1▾ SunlitDjango fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.1%
Last analysed / modified upstream
An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15.
django.core.mail.backends.smtp.EmailBackend in Django fails to prevent reuse of a partially-initialized connection after a failed STARTTLS handshake when fail_silently=True, which allows on-path network attackers to read email content via cleartext interception.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Kasper Dupont for reporting this issue.
django >= 5.2, < 5.2.15django >= 6.0, < 6.0.6Upgrade to a patched release:
django 5.2.15django 6.0.6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-5766Medium· 5.3Django has an Improper Handling of Length Parameter Inconsistency
CVE-2025-64460MediumDjango is vulnerable to DoS via XML serializer text extraction
CVE-2025-13372Medium· 4.3Django is vulnerable to SQL injection in column aliases
CVE-2025-64458High· 7.5Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2024-56374Medium· 5.8Django has a potential denial-of-service vulnerability in IPv6 validation
CVE-2025-26699Medium· 5.0Django vulnerable to Allocation of Resources Without Limits or Throttling