VulnSea

django has 39 CVEs on record between 2020 and 2026. Disclosures have slowed: 4 in the last 90 days after 10 in the 90 before. The busiest recent month was June 2026 with 5. The median CVSS is 5.3 (medium), with 1 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.3
Publish → KEV
Last 90 days
4 prev 10

Products

  • django 39
39
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

django vulnerabilities

CVEs affecting django, newest first. Open any entry for full detail, references, and exploit status.

39 CVEsRSS

CVE-2026-15830None
1mo ago

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as …

Sunlitdjango · djangoEPSS 1.3%via OSV
CVE-2026-53878Medium· 6.1
2mo ago

Django: DomainNameValidator permits newline characters that may enable HTTP header injection

Django: DomainNameValidator permits newline characters that may enable HTTP header injection

Sunlitdjango · djangoEPSS 0.33%via OSV
CVE-2026-53877Medium· 4.8
2mo ago

Django: GDALRaster may over-read heap memory when constructed from bytes

Django: GDALRaster may over-read heap memory when constructed from bytes

Sunlitdjango · djangoEPSS 0.44%via OSV
CVE-2026-48588Low· 3.1
2mo ago

Django: cache middleware may expose private responses when unrelated request cookies are present

Django: cache middleware may expose private responses when unrelated request cookies are present

Sunlitdjango · djangoEPSS 0.43%via OSV
CVE-2026-35193Low· 3.1
3mo ago

Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary

Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary

Sunlitdjango · djangoEPSS 0.37%via OSV
CVE-2026-6873Low· 3.1
3mo ago

Django: signed cookies are vulnerable to salt namespace collisions

Django: signed cookies are vulnerable to salt namespace collisions

Sunlitdjango · djangoEPSS 0.24%via OSV
CVE-2026-48587Low· 3.1
3mo ago

Django: has_vary_header may expose cached responses when Vary values contain whitespace

Django: has_vary_header may expose cached responses when Vary values contain whitespace

Sunlitdjango · djangoEPSS 0.37%via OSV
CVE-2026-8404Low· 3.1
3mo ago

Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling

Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling

Sunlitdjango · djangoEPSS 0.29%via OSV
CVE-2026-7666Low· 3.1
3mo ago

Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake

Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake

Sunlitdjango · djangoEPSS 0.15%via OSV
CVE-2026-5766Medium· 5.3
4mo ago

Django has an Improper Handling of Length Parameter Inconsistency

Django has an Improper Handling of Length Parameter Inconsistency

Sunlitdjango · djangoEPSS 0.42%via OSV
CVE-2026-6907Medium· 4.3
4mo ago

Django Uses Cache Containing Sensitive Information

Django Uses Cache Containing Sensitive Information

Sunlitdjango · djangoEPSS 0.36%via OSV
CVE-2026-4292Low· 2.7
5mo ago

Django vulnerable to privilege abuse in ModelAdmin.list_editable

Django vulnerable to privilege abuse in ModelAdmin.list_editable

Sunlitdjango · djangoEPSS 0.29%via OSV
CVE-2026-33034High· 7.5
5mo ago

Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit

Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit

Twilightdjango · djangoEPSS 0.77%via OSV
CVE-2026-33033Medium· 6.5PoC
5mo ago

Django has potential DoS via MultiPartParser through crafted multipart uploads

Django has potential DoS via MultiPartParser through crafted multipart uploads

Twilightdjango · djangoEPSS 0.88%via OSV
CVE-2026-25674Low· 3.7
6mo ago

Django has a Race Condition vulnerability

Django has a Race Condition vulnerability

Sunlitdjango · djangoEPSS 0.34%via OSV
CVE-2026-25673High· 7.5
6mo ago

Django vulnerable to Uncontrolled Resource Consumption

Django vulnerable to Uncontrolled Resource Consumption

Twilightdjango · djangoEPSS 0.73%via OSV
CVE-2026-1285Low
7mo ago

Django has Inefficient Algorithmic Complexity

Django has Inefficient Algorithmic Complexity

Sunlitdjango · djangoEPSS 1.0%via OSV
CVE-2025-14550Low
7mo ago

Django has Inefficient Algorithmic Complexity

Django has Inefficient Algorithmic Complexity

Sunlitdjango · djangoEPSS 1.0%via OSV
CVE-2025-13473Low
7mo ago

Django has Observable Timing Discrepancy

Django has Observable Timing Discrepancy

Sunlitdjango · djangoEPSS 0.74%via OSV
CVE-2025-64460Medium
9mo ago

Django is vulnerable to DoS via XML serializer text extraction

Django is vulnerable to DoS via XML serializer text extraction

Sunlitdjango · djangoEPSS 2.1%via OSV
CVE-2025-13372Medium· 4.3
9mo ago

Django is vulnerable to SQL injection in column aliases

Django is vulnerable to SQL injection in column aliases

Sunlitdjango · djangoEPSS 0.92%via OSV
CVE-2025-64458High· 7.5PoC
10mo ago

Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

Midnightdjango · djangoEPSS 1.9%via OSV
CVE-2025-57833High· 7.1PoC
1y ago

Django is subject to SQL injection through its column aliases

Django is subject to SQL injection through its column aliases

Midnightdjango · djangoEPSS 16%via OSV
CVE-2025-48432Medium· 4.0
1y ago

Django Improper Output Neutralization for Logs vulnerability

Django Improper Output Neutralization for Logs vulnerability

Sunlitdjango · djangoEPSS 0.75%via OSV
CVE-2025-32873Medium· 5.3PoC
1y ago

Django has a denial-of-service possibility in strip_tags()

Django has a denial-of-service possibility in strip_tags()

Twilightdjango · djangoEPSS 14%via OSV
CVE-2025-26699Medium· 5.0
1y ago

Django vulnerable to Allocation of Resources Without Limits or Throttling

Django vulnerable to Allocation of Resources Without Limits or Throttling

Sunlitdjango · djangoEPSS 0.81%via OSV
CVE-2024-56374Medium· 5.8
1y ago

Django has a potential denial-of-service vulnerability in IPv6 validation

Django has a potential denial-of-service vulnerability in IPv6 validation

Sunlitdjango · djangoEPSS 1.9%via OSV
CVE-2024-53908Critical· 9.8
1y ago

Django SQL injection in HasKey(lhs, rhs) on Oracle

Django SQL injection in HasKey(lhs, rhs) on Oracle

Midnightdjango · djangoEPSS 1.4%via OSV
CVE-2024-53907High· 7.5
1y ago

Django denial-of-service in django.utils.html.strip_tags()

Django denial-of-service in django.utils.html.strip_tags()

Twilightdjango · djangoEPSS 1.4%via OSV
CVE-2024-45231Low· 3.7
1y ago

Django allows enumeration of user e-mail addresses

Django allows enumeration of user e-mail addresses

Sunlitdjango · djangoEPSS 0.79%via OSV
django vulnerabilities (CVEs) · VulnSea