django vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-53877Mediumdjango: Django: GDALRaster may over-read heap memory when constructed from bytesCVE-2026-53878Mediumdjango: Django: DomainNameValidator permits newline characters that may enable HTTP header injectionCVE-2026-48588Lowdjango: Django: cache middleware may expose private responses when unrelated request cookies are presentCVE-2026-7666Lowdjango: Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshakeCVE-2026-6873Lowdjango: Django: signed cookies are vulnerable to salt namespace collisionsCVE-2026-8404Lowdjango: Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handlingCVE-2026-48587Lowdjango: Django: has_vary_header may expose cached responses when Vary values contain whitespaceCVE-2026-35193Lowdjango: Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from VaryCVE-2026-5766MediumDjango: Django has an Improper Handling of Length Parameter InconsistencyCVE-2026-6907LowDjango: Django Uses Cache Containing Sensitive InformationCVE-2026-35192LowDjango: Django Uses Persistent Cookies Containing Sensitive Information CVE-2026-4277LowDjango: Django vulnerable to privilege abuse in GenericInlineModelAdminCVE-2026-3902HighDjango: Django vulnerable to ASGI header spoofing via underscore/hyphen conflationCVE-2026-4292LowDjango: Django vulnerable to privilege abuse in ModelAdmin.list_editableCVE-2026-33034HighDjango: Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limitCVE-2026-33033MediumDjango: Django has potential DoS via MultiPartParser through crafted multipart uploadsCVE-2026-25673HighDjango: Django vulnerable to Uncontrolled Resource ConsumptionCVE-2026-25674LowDjango: Django has a Race Condition vulnerabilityCVE-2026-1312MediumDjango: Django has an SQL Injection issueCVE-2026-1287HighDjango: Django has an SQL Injection issueCVE-2026-1207HighDjango: Django has an SQL Injection issueCVE-2026-1285LowDjango: Django has Inefficient Algorithmic ComplexityCVE-2025-14550LowDjango: Django has Inefficient Algorithmic ComplexityCVE-2025-13473LowDjango: Django has Observable Timing DiscrepancyCVE-2025-64460MediumDjango: Django is vulnerable to DoS via XML serializer text extraction

Stop the waste.
Protect your environment with Kodem.