django has 39 CVEs on record between 2020 and 2026. Disclosures have slowed: 4 in the last 90 days after 10 in the 90 before. The busiest recent month was June 2026 with 5. The median CVSS is 5.3 (medium), with 1 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 4 prev 10
Products
- django 39
Worst active — by depth score
CVE-2024-39614High· 7.5Django vulnerable to Denial of Service59CVE-2025-64458High· 7.5Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows54CVE-2025-57833High· 7.1Django is subject to SQL injection through its column aliases54CVE-2024-53908Critical· 9.8Django SQL injection in HasKey(lhs, rhs) on Oracle54CVE-2020-9402High· 8.8SQL injection in Django53
django vulnerabilities
CVEs affecting django, newest first. Open any entry for full detail, references, and exploit status.
39 CVEsRSS
CVE-2026-15830NoneAn issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as …
CVE-2026-53878Medium· 6.1Django: DomainNameValidator permits newline characters that may enable HTTP header injection
Django: DomainNameValidator permits newline characters that may enable HTTP header injection
CVE-2026-53877Medium· 4.8Django: GDALRaster may over-read heap memory when constructed from bytes
Django: GDALRaster may over-read heap memory when constructed from bytes
CVE-2026-48588Low· 3.1Django: cache middleware may expose private responses when unrelated request cookies are present
Django: cache middleware may expose private responses when unrelated request cookies are present
CVE-2026-35193Low· 3.1Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary
Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary
CVE-2026-6873Low· 3.1Django: signed cookies are vulnerable to salt namespace collisions
Django: signed cookies are vulnerable to salt namespace collisions
CVE-2026-48587Low· 3.1Django: has_vary_header may expose cached responses when Vary values contain whitespace
Django: has_vary_header may expose cached responses when Vary values contain whitespace
CVE-2026-8404Low· 3.1Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
CVE-2026-7666Low· 3.1Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
CVE-2026-5766Medium· 5.3Django has an Improper Handling of Length Parameter Inconsistency
Django has an Improper Handling of Length Parameter Inconsistency
CVE-2026-6907Medium· 4.3Django Uses Cache Containing Sensitive Information
Django Uses Cache Containing Sensitive Information
CVE-2026-4292Low· 2.7Django vulnerable to privilege abuse in ModelAdmin.list_editable
Django vulnerable to privilege abuse in ModelAdmin.list_editable
CVE-2026-33034High· 7.5Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit
Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit
CVE-2026-33033Medium· 6.5PoCDjango has potential DoS via MultiPartParser through crafted multipart uploads
Django has potential DoS via MultiPartParser through crafted multipart uploads
CVE-2026-25674Low· 3.7Django has a Race Condition vulnerability
Django has a Race Condition vulnerability
CVE-2026-25673High· 7.5Django vulnerable to Uncontrolled Resource Consumption
Django vulnerable to Uncontrolled Resource Consumption
CVE-2026-1285LowDjango has Inefficient Algorithmic Complexity
Django has Inefficient Algorithmic Complexity
CVE-2025-14550LowDjango has Inefficient Algorithmic Complexity
Django has Inefficient Algorithmic Complexity
CVE-2025-13473LowDjango has Observable Timing Discrepancy
Django has Observable Timing Discrepancy
CVE-2025-64460MediumDjango is vulnerable to DoS via XML serializer text extraction
Django is vulnerable to DoS via XML serializer text extraction
CVE-2025-13372Medium· 4.3Django is vulnerable to SQL injection in column aliases
Django is vulnerable to SQL injection in column aliases
CVE-2025-64458High· 7.5PoCDjango has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2025-57833High· 7.1PoCDjango is subject to SQL injection through its column aliases
Django is subject to SQL injection through its column aliases
CVE-2025-48432Medium· 4.0Django Improper Output Neutralization for Logs vulnerability
Django Improper Output Neutralization for Logs vulnerability
CVE-2025-32873Medium· 5.3PoCDjango has a denial-of-service possibility in strip_tags()
Django has a denial-of-service possibility in strip_tags()
CVE-2025-26699Medium· 5.0Django vulnerable to Allocation of Resources Without Limits or Throttling
Django vulnerable to Allocation of Resources Without Limits or Throttling
CVE-2024-56374Medium· 5.8Django has a potential denial-of-service vulnerability in IPv6 validation
Django has a potential denial-of-service vulnerability in IPv6 validation
CVE-2024-53908Critical· 9.8Django SQL injection in HasKey(lhs, rhs) on Oracle
Django SQL injection in HasKey(lhs, rhs) on Oracle
CVE-2024-53907High· 7.5Django denial-of-service in django.utils.html.strip_tags()
Django denial-of-service in django.utils.html.strip_tags()
CVE-2024-45231Low· 3.7Django allows enumeration of user e-mail addresses
Django allows enumeration of user e-mail addresses