VulnSea

Django has 40 CVEs on record between 2020 and 2026. Disclosures have slowed: 5 in the last 90 days after 10 in the 90 before. The busiest recent month was June 2026 with 5. The median CVSS is 5.3 (medium), with 1 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
5.3
Publish → KEV
—
Last 90 days
5 prev 10

Weakness classes

Products

  • django 40
40
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

Django vulnerabilities

CVEs affecting Django, newest first. Open any entry for full detail, references, and exploit status.

40 CVEsRSS

CVE-2026-15307High· 8.8
1mo ago

Django GeoDjango spatial lookups allow file writes and outbound requests through GDAL raster parsing

Django GeoDjango spatial lookups allow file writes and outbound requests through GDAL raster parsing

▾ TwilightDjango · DjangoEPSS 1.1%via GHSA
CVE-2026-15830Medium· 5.3
1mo ago

Django GeoDjango vulnerable to denial of service through deeply nested geometry collections

Django GeoDjango vulnerable to denial of service through deeply nested geometry collections

▾ Sunlitdjango · djangoEPSS 0.76%via GHSA
CVE-2026-53878Medium· 6.1
2mo ago

Django: DomainNameValidator permits newline characters that may enable HTTP header injection

Django: DomainNameValidator permits newline characters that may enable HTTP header injection

▾ Sunlitdjango · djangoEPSS 0.33%via OSV
CVE-2026-53877Medium· 4.8
2mo ago

Django: GDALRaster may over-read heap memory when constructed from bytes

Django: GDALRaster may over-read heap memory when constructed from bytes

▾ Sunlitdjango · djangoEPSS 0.44%via OSV
CVE-2026-48588Low· 3.1
2mo ago

Django: cache middleware may expose private responses when unrelated request cookies are present

Django: cache middleware may expose private responses when unrelated request cookies are present

▾ Sunlitdjango · djangoEPSS 0.43%via OSV
CVE-2026-35193Low· 3.1
4mo ago

Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary

Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary

▾ Sunlitdjango · djangoEPSS 0.43%via OSV
CVE-2026-6873Low· 3.1
4mo ago

Django: signed cookies are vulnerable to salt namespace collisions

Django: signed cookies are vulnerable to salt namespace collisions

▾ Sunlitdjango · djangoEPSS 0.28%via OSV
CVE-2026-48587Low· 3.1
4mo ago

Django: has_vary_header may expose cached responses when Vary values contain whitespace

Django: has_vary_header may expose cached responses when Vary values contain whitespace

▾ Sunlitdjango · djangoEPSS 0.43%via OSV
CVE-2026-8404Low· 3.1
4mo ago

Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling

Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling

▾ Sunlitdjango · djangoEPSS 0.43%via OSV
CVE-2026-7666Low· 3.1
4mo ago

Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake

Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake

▾ Sunlitdjango · djangoEPSS 0.21%via OSV
CVE-2026-5766Medium· 5.3
4mo ago

Django has an Improper Handling of Length Parameter Inconsistency

Django has an Improper Handling of Length Parameter Inconsistency

▾ Sunlitdjango · djangoEPSS 0.52%via OSV
CVE-2026-6907Medium· 4.3
4mo ago

Django Uses Cache Containing Sensitive Information

Django Uses Cache Containing Sensitive Information

▾ Sunlitdjango · djangoEPSS 0.44%via OSV
CVE-2026-4292Low· 2.7
5mo ago

Django vulnerable to privilege abuse in ModelAdmin.list_editable

Django vulnerable to privilege abuse in ModelAdmin.list_editable

▾ Sunlitdjango · djangoEPSS 0.36%via OSV
CVE-2026-33034High· 7.5
5mo ago

Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit

Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit

▾ Twilightdjango · djangoEPSS 0.85%via OSV
CVE-2026-33033Medium· 6.5PoC
5mo ago

Django has potential DoS via MultiPartParser through crafted multipart uploads

Django has potential DoS via MultiPartParser through crafted multipart uploads

▾ Twilightdjango · djangoEPSS 0.88%via OSV
CVE-2026-25674Low· 3.7
7mo ago

Django has a Race Condition vulnerability

Django has a Race Condition vulnerability

▾ Sunlitdjango · djangoEPSS 0.33%via OSV
CVE-2026-25673High· 7.5
7mo ago

Django vulnerable to Uncontrolled Resource Consumption

Django vulnerable to Uncontrolled Resource Consumption

▾ Twilightdjango · djangoEPSS 1.1%via OSV
CVE-2026-1285Low
8mo ago

Django has Inefficient Algorithmic Complexity

Django has Inefficient Algorithmic Complexity

▾ Sunlitdjango · djangoEPSS 1.1%via OSV
CVE-2025-14550Low
8mo ago

Django has Inefficient Algorithmic Complexity

Django has Inefficient Algorithmic Complexity

▾ Sunlitdjango · djangoEPSS 1.1%via OSV
CVE-2025-13473Low
8mo ago

Django has Observable Timing Discrepancy

Django has Observable Timing Discrepancy

▾ Sunlitdjango · djangoEPSS 0.76%via OSV
CVE-2025-64460Medium
10mo ago

Django is vulnerable to DoS via XML serializer text extraction

Django is vulnerable to DoS via XML serializer text extraction

▾ Sunlitdjango · djangoEPSS 2.1%via OSV
CVE-2025-13372Medium· 4.3
10mo ago

Django is vulnerable to SQL injection in column aliases

Django is vulnerable to SQL injection in column aliases

▾ Sunlitdjango · djangoEPSS 0.92%via OSV
CVE-2025-64458High· 7.5PoC
11mo ago

Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

▾ Midnightdjango · djangoEPSS 1.9%via OSV
CVE-2025-57833High· 7.1PoC
1y ago

Django is subject to SQL injection through its column aliases

Django is subject to SQL injection through its column aliases

▾ Midnightdjango · djangoEPSS 17%via OSV
CVE-2025-48432Medium· 4.0
1y ago

Django Improper Output Neutralization for Logs vulnerability

Django Improper Output Neutralization for Logs vulnerability

▾ Sunlitdjango · djangoEPSS 0.75%via OSV
CVE-2025-32873Medium· 5.3PoC
1y ago

Django has a denial-of-service possibility in strip_tags()

Django has a denial-of-service possibility in strip_tags()

▾ Twilightdjango · djangoEPSS 14%via OSV
CVE-2025-26699Medium· 5.0
1y ago

Django vulnerable to Allocation of Resources Without Limits or Throttling

Django vulnerable to Allocation of Resources Without Limits or Throttling

▾ Sunlitdjango · djangoEPSS 0.83%via OSV
CVE-2024-56374Medium· 5.8
1y ago

Django has a potential denial-of-service vulnerability in IPv6 validation

Django has a potential denial-of-service vulnerability in IPv6 validation

▾ Sunlitdjango · djangoEPSS 1.9%via OSV
CVE-2024-53908Critical· 9.8
1y ago

Django SQL injection in HasKey(lhs, rhs) on Oracle

Django SQL injection in HasKey(lhs, rhs) on Oracle

▾ Midnightdjango · djangoEPSS 1.4%via OSV
CVE-2024-53907High· 7.5
1y ago

Django denial-of-service in django.utils.html.strip_tags()

Django denial-of-service in django.utils.html.strip_tags()

▾ Twilightdjango · djangoEPSS 1.4%via OSV
Django vulnerabilities (CVEs) · VulnSea