Arsip dari masalah keamananLink to this heading

Tim pengembangan Django memiliki komitmen yang kuat untuk bertanggung jawab melaorkan dan menyingkap dari masalah terkait-keamanan, sebagai diuraikan di Django's security policies.

Sebagai bagian dari komitmen itu, kami merawat daftar riwayat berikut dari masalah yang telah diperbaiki dan diungkapkan. Untuk setiap masalah, daftar dibawah termasuk tanggal, gambaran singkat CVE identifier jika diberlakukan, sebuah daftar dari versi terpengaruh, sebuah tautan pada pengungkapan penuh dan tautan ke tambalan-tambalan yang sesuai.

Beberapa peringatan penting berlaku pada informasi ini:

  • Daftar dari versi terpengaruh termasuk hanya versi itu dari Django yang stabil, terbitan dukungan-keamanan pada saat dari penyingkapan. Ini berarti versi terlama (yang dukungan keamanan telah berakhir) dan versi yang berada di pra-terbitan keadaan (alpha/beta/RC) pada saat dari penyingkapan mungkin telah terpengaruh, tetapi tidak terdaftar.

  • Proyek Django terkadang menerbitkan saran keamanan, menunjuk kemungkinan masalah keamanan yang dapat muncul dari konfigurasi tidak sesuai atau dari masalah-masalah lain diluar Django itu sendiri. Beberapa dari saran-saran ini telah menerima CVE; ketika itu adalah kasus, mereka didaftarkan disini, tetapi karena mereka tidak mempunyai tambalan atau terbitan yang mendampingi, hanya gambaran, penyingkapan dan CVE akan didaftarkan.

Masalah dibawah pengolahan keamanan DjangoLink to this heading

All security issues have been handled under versions of Django's security process. These are listed below.

August 4, 2026 - CVE 2026-15307Link to this heading

Server-side file-write and request forgery via spatial lookups. Full description

August 4, 2026 - CVE 2026-15337Link to this heading

Potential denial-of-service vulnerability in check_for_language(). Full description

August 4, 2026 - CVE 2026-15830Link to this heading

Potential denial-of-service vulnerability via nested geometry collections. Full description

August 4, 2026 - CVE 2026-15920Link to this heading

Potential cross-site scripting via URLField values in the admin. Full description

July 7, 2026 - CVE 2026-48588Link to this heading

Potential exposure of private data via cached Set-Cookie response. Full description

July 7, 2026 - CVE 2026-53877Link to this heading

Heap buffer over-read in GDALRaster. Full description

July 7, 2026 - CVE 2026-53878Link to this heading

Header injection possibility since DomainNameValidator accepted newlines in input. Full description

June 3, 2026 - CVE 2026-6873Link to this heading

Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie. Full description

June 3, 2026 - CVE 2026-7666Link to this heading

Potential unencrypted email transmission via STARTTLS in the SMTP backend. Full description

June 3, 2026 - CVE 2026-8404Link to this heading

Potential exposure of private data via case-sensitive Cache-Control directives in UpdateCacheMiddleware. Full description

June 3, 2026 - CVE 2026-35193Link to this heading

Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddleware. Full description

June 3, 2026 - CVE 2026-48587Link to this heading

Potential exposure of private data via whitespace padding in Vary header. Full description

May 5, 2026 - CVE 2026-5766Link to this heading

Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass. Full description

May 5, 2026 - CVE 2026-35192Link to this heading

Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST. Full description

May 5, 2026 - CVE 2026-6907Link to this heading

Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware. Full description

April 7, 2026 - CVE 2026-3902Link to this heading

ASGI header spoofing via underscore/hyphen conflation. Full description

April 7, 2026 - CVE 2026-4277Link to this heading

Privilege abuse in GenericInlineModelAdmin. Full description

April 7, 2026 - CVE 2026-4292Link to this heading

Privilege abuse in ModelAdmin.list_editable. Full description

April 7, 2026 - CVE 2026-33033Link to this heading

Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload. Full description

April 7, 2026 - CVE 2026-33034Link to this heading

Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass. Full description

March 3, 2026 - CVE 2026-25673Link to this heading

Potential denial-of-service vulnerability in URLField via Unicode normalization on Windows. Full description

March 3, 2026 - CVE 2026-25674Link to this heading

Potential incorrect permissions on newly created file system objects. Full description

February 3, 2026 - CVE 2025-13473Link to this heading

Username enumeration through timing difference in mod_wsgi authentication handler. Full description

February 3, 2026 - CVE 2025-14550Link to this heading

Potential denial-of-service vulnerability via repeated headers when using ASGI. Full description

February 3, 2026 - CVE 2026-1207Link to this heading

Potential SQL injection via raster lookups on PostGIS. Full description

February 3, 2026 - CVE 2026-1285Link to this heading

Potential denial-of-service vulnerability in django.utils.text.Truncator HTML methods. Full description

February 3, 2026 - CVE 2026-1287Link to this heading

Potential SQL injection in column aliases via control characters. Full description

February 3, 2026 - CVE 2026-1312Link to this heading

Potential SQL injection via QuerySet.order_by and FilteredRelation. Full description

December 2, 2025 - CVE 2025-13372Link to this heading

Potential SQL injection in FilteredRelation column aliases on PostgreSQL. Full description

December 2, 2025 - CVE 2025-64460Link to this heading

Potential denial-of-service vulnerability in XML serializer text extraction. Full description

November 5, 2025 - CVE 2025-64458Link to this heading

Potential denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows. Full description

November 5, 2025 - CVE 2025-64459Link to this heading

Potential SQL injection via _connector keyword argument in QuerySet and Q objects. Full description

October 1, 2025 - CVE 2025-59681Link to this heading

Potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() on MySQL and MariaDB. Full description

October 1, 2025 - CVE 2025-59682Link to this heading

Potential partial directory-traversal via archive.extract(). Full description

September 3, 2025 - CVE 2025-57833Link to this heading

Potential SQL injection in FilteredRelation column aliases. Full description

June 4, 2025 - CVE 2025-48432Link to this heading

Potential log injection via unescaped request path. Full description

There was an additional hardening with new patch releases published on June 10, 2025. Full description

May 7, 2025 - CVE 2025-32873Link to this heading

Denial-of-service possibility in strip_tags(). Full description

April 2, 2025 - CVE 2025-27556Link to this heading

Potential denial-of-service vulnerability in LoginView, LogoutView, and set_language() on Windows. Full description

March 6, 2025 - CVE 2025-26699Link to this heading

Potential denial-of-service in django.utils.text.wrap(). Full description

January 14, 2025 - CVE 2024-56374Link to this heading

Potential denial-of-service vulnerability in IPv6 validation. Full description

December 4, 2024 - CVE 2024-53907Link to this heading

Potensi denial-of-service di django.utils.html.strip_tags(). Full description

December 4, 2024 - CVE 2024-53908Link to this heading

Potential SQL injection in HasKey(lhs, rhs) on Oracle. Full description

September 3, 2024 - CVE 2024-45231Link to this heading

Potential user email enumeration via response status on password reset. Full description

September 3, 2024 - CVE 2024-45230Link to this heading

Potensi rentan denial-of-service di django.utils.html.urlize(). Full description

August 6, 2024 - CVE 2024-42005Link to this heading

Potential SQL injection in QuerySet.values() and values_list(). Full description

August 6, 2024 - CVE 2024-41991Link to this heading

Potensi rentan denial-of-service django.utils.html.urlize() and AdminURLFieldWidget. Full description

August 6, 2024 - CVE 2024-41990Link to this heading

Potensi rentan denial-of-service django.utils.html.urlize(). Full description

August 6, 2024 - CVE 2024-41989Link to this heading

Potential memory exhaustion in django.utils.numberformat.floatformat(). Full description

July 9, 2024 - CVE 2024-39614Link to this heading

Potential denial-of-service in django.utils.translation.get_supported_language_variant(). Full description

July 9, 2024 - CVE 2024-39330Link to this heading

Potential directory-traversal in django.core.files.storage.Storage.save(). Full description

July 9, 2024 - CVE 2024-39329Link to this heading

Username enumeration through timing difference for users with unusable passwords. Full description

July 9, 2024 - CVE 2024-38875Link to this heading

Potensi denial-of-service di django.utils.html.urlize(). Full description

March 4, 2024 - CVE 2024-27351Link to this heading

Potential regular expression denial-of-service in django.utils.text.Truncator.words(). Full description

February 6, 2024 - CVE 2024-24680Link to this heading

Potential denial-of-service in intcomma template filter. Full description

November 1, 2023 - CVE 2023-46695Link to this heading

Potential denial of service vulnerability in UsernameField on Windows. Full description

October 4, 2023 - CVE 2023-43665Link to this heading

Denial-of-service possibility in django.utils.text.Truncator. Full description

September 4, 2023 - CVE 2023-41164Link to this heading

Potential denial of service vulnerability in django.utils.encoding.uri_to_iri(). Full description

July 3, 2023 - CVE 2023-36053Link to this heading

Potential regular expression denial of service vulnerability in EmailValidator/URLValidator. Full description

May 3, 2023 - CVE 2023-31047Link to this heading

Potential bypass of validation when uploading multiple files using one form field. Full description

February 14, 2023 - CVE 2023-24580Link to this heading

Potential denial-of-service vulnerability in file uploads. Full description

February 1, 2023 - CVE 2023-23969Link to this heading

Potential denial-of-service via Accept-Language headers. Full description

October 4, 2022 - CVE 2022-41323Link to this heading

Potential denial-of-service vulnerability in internationalized URLs. Full description

August 3, 2022 - CVE 2022-36359Link to this heading

Potential reflected file download vulnerability in FileResponse. Full description

July 4, 2022 - CVE 2022-34265Link to this heading

Potensi suntikan SQL melalui Trunc(kind) and Extract(lookup_name) arguments. Full description

April 11, 2022 - CVE 2022-28346Link to this heading

Potensi suntikan SQL dalam QuerySet.annotate(), aggregate(), and extra(). Full description

April 11, 2022 - CVE 2022-28347Link to this heading

Potensi suntikan SQL melalui QuerySet.explain(**options) on PostgreSQL. Full description

February 1, 2022 - CVE 2022-22818Link to this heading

Possible XSS via {% debug %} template tag. Full description

Versi terpengaruhLink to this heading

1 Februari 2022 - CVE 2022-23833Link to this heading

Denial-of-service possibility in file uploads. Full description

Versi terpengaruhLink to this heading

4 Januari 2022 - CVE 2021-45452Link to this heading

Potential directory-traversal via Storage.save(). Full description

Versi terpengaruhLink to this heading

January 4, 2022 - CVE 2021-45116Link to this heading

Informasi potensial disingkap dalam saringan cetakan dictsort. Full description

Versi terpengaruhLink to this heading

4 Januari 2022 - CVE 2021-45115Link to this heading

Denial-of-service possibility in UserAttributeSimilarityValidator. Full description

Versi terpengaruhLink to this heading

7 Desember 2021 - CVE 2021-44420Link to this heading

Potensi celah keamanan akses hulu yang didasarkan pada jalur URL. Full description

Versi terpengaruhLink to this heading

1 Juli 2021 - CVE 2021-35042Link to this heading

Potensi injeksi SQL melalui input QuerySet.order_by() yang tidak disanitasi. Full description

Versi terpengaruhLink to this heading

2 Juni 2021 - CVE 2021-33203Link to this heading

Potensi kerentanan directory traversal melalui admindocs. Full description

Versi terpengaruhLink to this heading

June 2, 2021 - CVE 2021-33571Link to this heading

Possible indeterminate SSRF, RFI, and LFI attacks since validators accepted leading zeros in IPv4 addresses. Full description

Versi terpengaruhLink to this heading

May 6, 2021 - CVE 2021-32052Link to this heading

Header injection possibility since URLValidator accepted newlines in input on Python 3.9.5+. Full description

Versi terpengaruhLink to this heading

May 4, 2021 - CVE 2021-31542Link to this heading

Potential directory-traversal via uploaded files. Full description

Versi terpengaruhLink to this heading

April 6, 2021 - CVE 2021-28658Link to this heading

Potential directory-traversal via uploaded files. Full description

Versi terpengaruhLink to this heading

February 19, 2021 - CVE 2021-23336Link to this heading

Web cache poisoning via django.utils.http.limited_parse_qsl(). Full description

Versi terpengaruhLink to this heading

1 Februari 2021 - CVE 2021-3281Link to this heading

Potensi kerentanan directory traversal melalui archive.extract(). Full description

Versi terpengaruhLink to this heading

1 September 2020 - CVE 2020-24584Link to this heading

Peningkatan hak akses pada direktori tingkat menengah cache sistem file di Python 3.7+. Full description

Versi terpengaruhLink to this heading

1 September 2020 - CVE 2020-24583Link to this heading

Izin yang salah pada direktori tingkat menengah di Python 3.7+. ``Full description <https://www.djangoproject.com/weblog/2020/sep/01/security-releases/>`__

Versi terpengaruhLink to this heading

June 3, 2020 - CVE 2020-13596Link to this heading

Kemungkinan XSS melalui admin ForeignKeyRawIdWidget. Full description

Versi terpengaruhLink to this heading

June 3, 2020 - CVE 2020-13254Link to this heading

Potensi kebocoran data melalui kunci memcached yang salah format. Full description

Versi terpengaruhLink to this heading

4 Maret 2020 - CVE 2020-9402Link to this heading

Potensi injeksi SQL melalui parameter tolerance dalam fungsi dan agregasi GIS di Oracle. Full description

Versi terpengaruhLink to this heading

3 Februari 2020 - CVE 2020-7471Link to this heading

Potensi serangan SQL injection melalui StringAgg(delimiter). Full description

Versi terpengaruhLink to this heading

December 18, 2019 - CVE 2019-19844Link to this heading

Potential account hijack via password reset form. Full description

Versi terpengaruhLink to this heading

December 2, 2019 - CVE 2019-19118Link to this heading

Privilege escalation in the Django admin. Full description

Versi terpengaruhLink to this heading

August 1, 2019 - CVE 2019-14235Link to this heading

Potensi kelelahan memori dalam django.utils.encoding.uri_to_iri(). Full description

Versi terpengaruhLink to this heading

August 1, 2019 - CVE 2019-14234Link to this heading

Kemungkinan suntikan SQL dalam pencarian kunci dan indeks untuk JSONField/HStoreField. Full description

Versi terpengaruhLink to this heading

August 1, 2019 - CVE 2019-14233Link to this heading

Kemungkinan Denial-of-service dalam strip_tags(). Full description

Versi terpengaruhLink to this heading

August 1, 2019 - CVE 2019-14232Link to this heading

Denial-of-service possibility in django.utils.text.Truncator. Full description

Versi terpengaruhLink to this heading

July 1, 2019 - CVE 2019-12781Link to this heading

Incorrect HTTP detection with reverse-proxy connecting via HTTPS. Full description

Versi terpengaruhLink to this heading

June 3, 2019 - CVE 2019-12308Link to this heading

XSS via "Current URL" link generated by AdminURLFieldWidget. Full description

Versi terpengaruhLink to this heading

June 3, 2019 - CVE 2019-11358Link to this heading

Prototype pollution in bundled jQuery. Full description

Versi terpengaruhLink to this heading

February 11, 2019 - CVE 2019-6975Link to this heading

Memory exhaustion in django.utils.numberformat.format(). Full description

Versi terpengaruhLink to this heading

January 4, 2019 - CVE 2019-3498Link to this heading

Content spoofing possibility in the default 404 page. Full description

Versi terpengaruhLink to this heading

October 1, 2018 - CVE 2018-16984Link to this heading

Password hash disclosure to "view only" admin users. Full description

Versi terpengaruhLink to this heading

August 1, 2018 - CVE 2018-14574Link to this heading

Open redirect possibility in CommonMiddleware. Full description

Versi terpengaruhLink to this heading

March 6, 2018 - CVE 2018-7537Link to this heading

Denial-of-service possibility in truncatechars_html and truncatewords_html template filters. Full description

Versi terpengaruhLink to this heading

March 6, 2018 - CVE 2018-7536Link to this heading

Denial-of-service possibility in urlize and urlizetrunc template filters. Full description

Versi terpengaruhLink to this heading

February 1, 2018 - CVE 2018-6188Link to this heading

Information leakage in AuthenticationForm. Full description

Versi terpengaruhLink to this heading

5 September 2017 - CVE 2017-12794Link to this heading

Kemungkinan XSS di melacak kembali bagian dari halaman teknis mencari kesalahan 500. Full description

Versi terpengaruhLink to this heading

4 April 2017 - CVE 2017-7234Link to this heading

Membuka kerentanan pangalihan dalam django.views.static.serve(). Full description

Versi terpengaruhLink to this heading

4 April 2017 - CVE 2017-7233Link to this heading

Dibuka pengalihan dan kemungkinan serangan XSS melalui URL pengalihan numerik disokong-pengguna. Full description

Versi terpengaruhLink to this heading

1 November 2016 - CVE 2016-9014Link to this heading

Kerentanan mengikat kembali ketika DEBUG=True. Full description

Versi terpengaruhLink to this heading

1 November 2016 - CVE 2016-9013Link to this heading

Pengguna dengan sandi kode keras sandi dibuat ketika menjalankan percobaan pada Oracle. Full description

Versi terpengaruhLink to this heading

26 September 2016 - CVE 2016-7401Link to this heading

Pemotongan perlindungan CSRF pada situs dengan Google Analytics. Full description

Versi terpengaruhLink to this heading

18 Juli 2016 - CVE 2016-6186Link to this heading

XSS dalam popup terkait tambah/rubah admin. Full description

Versi terpengaruhLink to this heading

1 Maret 2016 - CVE 2016-2513Link to this heading

Pendaftaran pengguna melalui perbedaan pewaktu pada peningkatan faktor pekerjaan pengacak sandi. Full description

Versi terpengaruhLink to this heading

1 Maret 2016 - CVE 2016-2512Link to this heading

Pengalihan dan kemungkinsn serangan XSS jelek melalui URL pengalihan diberikan-pengguna mengandung autentifikasi dasar. Full description

Versi terpengaruhLink to this heading

1 Februari 2016 - CVE 2016-2048Link to this heading

Pengguna dengan "change" tetapi tidak "add" perizinan dapat membuat obyek untuk ModelAdmin dengan save_as=True. Full description

Versi terpengaruhLink to this heading

24 November 2015 - CVE 2015-8213Link to this heading

Menyetel kemungkinan bocor di penyaring cetakan date. Full description

Versi terpengaruhLink to this heading

18 Agustus 2015 - CVE 2015-5963 / CVE 2015-5964Link to this heading

Kemungkinan denial-of-service di tampilan logout() dengan mengisi toko sesi. Full description

Versi terpengaruhLink to this heading

8 Juli 2015 - CVE 2015-5145Link to this heading

Kemungkinan denial-of-service di pengesahan URL. Full description

Versi terpengaruhLink to this heading

8 Juli 2015 - CVE 2015-5144Link to this heading

Kemungkinan suntikan kepala sejak pengesah menerima baris baru di masukan. Full description

Versi terpengaruhLink to this heading

8 Juli 2015 - CVE 2015-5143Link to this heading

Kemungkinan denial-of-service dengan mengisi toko sesi. Full description

Versi terpengaruhLink to this heading

20 Mei 2015 - CVE 2015-3982Link to this heading

Diperbaiki pembilasan sesi di backend cached_db. Full description

Versi terpengaruhLink to this heading

18 Maret 2015 - CVE 2015-2317Link to this heading

Dikurangi kemungkinan serangan XSS melalui URL pengalihan diberikan-pengguna. Full description

Versi terpengaruhLink to this heading

18 Maret 2015 - CVE 2015-2316Link to this heading

Kemungkinan denial-of-service dengan strip_tags(). Full description

Versi terpengaruhLink to this heading

9 Maret 2015 - CVE 2015-2241Link to this heading

Serangan XSS melalui sifat di ModelAdmin.readonly_fields. Full description

Versi terpengaruhLink to this heading

13 januari 2015 - CVE 2015-0222Link to this heading

Denial-of-service basisdata dengan ModelMultipleChoiceField. Full description

Versi terpengaruhLink to this heading

13 Januari 2015 - CVE 2015-0221Link to this heading

Serangan denial-of-service terhadap django.views.static.serve(). Full description

Versi terpengaruhLink to this heading

13 Januari 2015 - CVE 2015-0220Link to this heading

Dikurangi kemungkinan serangan XSS melalui URL pengalihan diberikan-pengguna. Full description

Versi terpengaruhLink to this heading

13 Januari 2015 - CVE 2015-0219Link to this heading

Menipu kepala WSGI melalui garis bawah/penggabungan tanda garis. Full description

Versi terpengaruhLink to this heading

20 Agustus 2014 - CVE 2014-0483Link to this heading

Kebocoran data melalui memanipulasi querystring di admin. Full description

Versi terpengaruhLink to this heading

20 Agustus 2014 - CVE 2014-0482Link to this heading

Pembajakan sesi RemoteUserMiddleware. Full description

Versi terpengaruhLink to this heading

20 Agustus 2014 - CVE 2014-0481Link to this heading

Unggah berkas denial of service. Full description

Versi terpengaruhLink to this heading

20 Agustus 2014 - CVE 2014-0480Link to this heading

reverse()` dapat membangkitkan URL menunjuk ke rumah lain. Full description

Versi terpengaruhLink to this heading

18 Mei 2014 - CVE 2014-3730Link to this heading

URL jelek dari masukan pengguna tidak benar disahkan. Full description

Versi terpengaruhLink to this heading

18 Mei 2014 - CVE 2014-1418Link to this heading

Tembolok mungkin diizinkan untuk menyimpan dan melayani data pribadi. Full description

Versi terpengaruhLink to this heading

21 April 2014 - CVE 2014-0474Link to this heading

Typecast MySQL menyebabkan hasil permintaan yang tidak diharapkan. Full description

Versi terpengaruhLink to this heading

21 April 2014 - CVE 2014-0473Link to this heading

Cache dari halaman anonim dapat mengungkap token CSRF. Full description

Versi terpengaruhLink to this heading

21 April 2014 - CVE 2014-0472Link to this heading

Pengerjaan kode tidak diharapkan menggunakan reverse(). Full description

Versi terpengaruhLink to this heading

14 September 2013 - CVE 2013-1443Link to this heading

Denial-of-service melalui sandi besar. Full description

Versi terpengaruhLink to this heading

10 September 2013 - CVE 2013-4315Link to this heading

Lintasan-direktori melalui etiket cetakan ssi. Full description

Versi terpengaruhLink to this heading

13 Agustus 2013 - CVE 2013-6044Link to this heading

Kemungkinan XSS melalui skema pengalihan URL tidak disahkan. Full description

Versi terpengaruhLink to this heading

13 Agustus 2013 - CVE 2013-4249Link to this heading

XSS melalui nilai-nilai URLField dipercaya admin. Full description

Versi terpengaruhLink to this heading

19 Februari 2013 - CVE 2013-0306Link to this heading

Denial-of-service melalui memotong max_num formset. Full description

Versi terpengaruhLink to this heading

19 Februari 2013 - CVE 2013-0305Link to this heading

Kebocoran informasi melalui catatan riwayat admin. Full description

Versi terpengaruhLink to this heading

19 Februari 2013 - CVE 2013-1664 / CVE 2013-1665Link to this heading

Serangan berdasarkan-masukan terhadap pustaka XML Python. Full description

Versi terpengaruhLink to this heading

Februari 19, 2013 - No CVELink to this heading

Tambahan pengerasan dari penanganan kepala Host. Full description

Versi terpengaruhLink to this heading

Desember 10, 2012 - No CVE 2Link to this heading

Tambahan pengerasan dari pengalihan pengesahan. Full description

Versi terpengaruhLink to this heading

Desember 10, 2012 - No CVE 1Link to this heading

Tambahan pengerasan dari penanganan kepala Host. Full description

Versi terpengaruhLink to this heading

17 Oktober 2012 - CVE 2012-4520Link to this heading

Peracunan kepala Host. Full description

Versi terpengaruhLink to this heading

30 Juli 2012 - CVE 2012-3444Link to this heading

Denial-of-service melalui berkas-berkas gambar. Full description

Versi terpengaruhLink to this heading

30 Juli 2012 - CVE 2012-3443Link to this heading

Denial-of-service melalui berkas-berkas gambar termampatkan. Full description

Versi terpengaruhLink to this heading

30 Juli 2012 - CVE 2012-3442Link to this heading

XSS melalui kegagalan untuk mensahkan skema pengalihan. Full description

Versi terpengaruhLink to this heading

9 September 2011 - CVE 2011-4140Link to this heading

Kemungkinan CSRF melalui kepala Host. Full description

Versi terpengaruhLink to this heading

Pemberitahuan ini hanya saran, jadi tidak ada tambalan diterbitkan.

  • Django 1.2

  • Django 1.3

9 September 2011 - CVE 2011-4139Link to this heading

Peracunan cache kepala Host. Full description

Versi terpengaruhLink to this heading

9 September 2011 - CVE 2011-4138Link to this heading

Pengeluaran permintaan kebocoran/berubah-ubah informasi melalui URLField.verify_exists. Full description

Versi terpengaruhLink to this heading

9 September 2011 - CVE 2011-4137Link to this heading

Denial-of-service melalui URLField.verify_exists. Full description

Versi terpengaruhLink to this heading

9 September 2011 - CVE 2011-4136Link to this heading

Manipulasi sesi ketika menggunakan sesi backend-cache-memori. Full description

Versi terpengaruhLink to this heading

8 Februari 2011 - CVE 2011-0698Link to this heading

Lintasan-direktori pada Windows melalui penanganan pemisah-jalur tidak benar. Full description

Versi terpengaruhLink to this heading

8 Februari 2011 - CVE 2011-0697Link to this heading

XSS melalui nama-nama tidak dibersihkan dari berkas-berkas terunggah. Full description

Versi terpengaruhLink to this heading

8 Februari 2011 - CVE 2011-0696Link to this heading

CSRF melalui kepala HTTP yang ditempa. Full description

Versi terpengaruhLink to this heading

  • commit:(patch) <408c5c873ce1437c7eee9544ff279ecbad7e150a> Django 1.1

  • (patch) Django 1.2

22 Desember 2010 - CVE 2010-4535Link to this heading

Denial-of-service di mekanisme setel kembali-sandi. Full description

Versi terpengaruhLink to this heading

22 Desember 2010 - CVE 2010-4534Link to this heading

Kebocoran informasi di antarmuka administratif. Full description

Versi terpengaruhLink to this heading

8 September 2010 - CVE 2010-3082Link to this heading

XSS melalui nilai kue tidak aman dipercaya. Full description

Versi terpengaruhLink to this heading

9 Oktober 2009 - CVE 2009-3695Link to this heading

Denial-of-service melalui penampilan pernyataan regular patologi. Full description

Versi terpengaruhLink to this heading

28 Juli 2009 - CVE 2009-2659Link to this heading

Lintasan-direktori dalam penangan media peladen pengembangan. Full description

Versi terpengaruhLink to this heading

2 September 2008 - CVE 2008-3909Link to this heading

CSRF melalui pemeliharaan dari data POST selama masuk admin. Full description

Versi terpengaruhLink to this heading

14 mei 2008 - CVE 2008-2302Link to this heading

XSS melalui pengalihan masuk admin. Full description

Versi terpengaruhLink to this heading

26 Oktober 2007 - CVE 2007-5712Link to this heading

Denial-of-service melalui kepala Accept-Language besar-berubah-ubah. Full description

Versi terpengaruhLink to this heading

Masalah-masalah pada sebelum pengolahan keamanan DjangoLink to this heading

Beberapa masalah keamanan ditangani sebelum Django telah menyusun pengolahan keamanan yang digunakan. Untuk ini, terbitan baru mungkin tidak telah dikeluarkan pada saat itu dan CVE mungkin tidak telah ditentukan.

21 Januari 2007 - CVE 2007-0405Link to this heading

Kejelasan "caching" dari pengguna terautentifikasi. Full description

Versi terpengaruhLink to this heading

16 Agustus 2006 - CVE 2007-0404Link to this heading

Masalah pengesahan nama berkas di terjemahan kerangka kerja. Full description

Versi terpengaruhLink to this heading