安全问题档案Link to this heading

Django 的开发团队致力于负责任地报告和披露与安全相关的问题,正如 Django 的安全政策 所概述的那样。

作为该承诺的一部分,我们保留了以下已修复和披露的历史问题清单。对于每个问题,下面的列表包括日期、简要描述、CVE 标识符 (如果适用)、受影响版本的列表、到完整披露的链接以及到适当补丁的链接。

一些重要的注意事项适用于这些信息:

  • 受影响的版本列表只包括那些在披露时有稳定的、安全支持的版本的 Django。这意味着旧版本(其安全支持已经过期)和在披露时处于发布前(alpha/beta/RC)状态的版本可能会受到影响,但没有被列出。

  • Django 项目有时会发布安全公告,指出潜在的安全问题,这些问题可能是由于配置不当或 Django 本身以外的其他问题造成的。有些安全公告已经收到了 CVE,在这种情况下,它们会被列在这里,但由于它们没有附带的补丁或版本,所以只会列出描述、披露和 CVE。

Django 的安全流程下的问题Link to this heading

所有的安全问题都已经在 Django 的安全进程的版本下处理。这些版本列举如下。

April 7, 2026 - CVE 2026-3902Link to this heading

ASGI header spoofing via underscore/hyphen conflation. Full description

April 7, 2026 - CVE 2026-4277Link to this heading

Privilege abuse in GenericInlineModelAdmin. Full description

April 7, 2026 - CVE 2026-4292Link to this heading

Privilege abuse in ModelAdmin.list_editable. Full description

April 7, 2026 - CVE 2026-33033Link to this heading

Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload. Full description

April 7, 2026 - CVE 2026-33034Link to this heading

Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass. Full description

March 3, 2026 - CVE 2026-25673Link to this heading

Potential denial-of-service vulnerability in URLField via Unicode normalization on Windows. Full description

March 3, 2026 - CVE 2026-25674Link to this heading

Potential incorrect permissions on newly created file system objects. Full description

February 3, 2026 - CVE 2025-13473Link to this heading

Username enumeration through timing difference in mod_wsgi authentication handler. Full description

February 3, 2026 - CVE 2025-14550Link to this heading

Potential denial-of-service vulnerability via repeated headers when using ASGI. Full description

February 3, 2026 - CVE 2026-1207Link to this heading

Potential SQL injection via raster lookups on PostGIS. Full description

February 3, 2026 - CVE 2026-1285Link to this heading

Potential denial-of-service vulnerability in django.utils.text.Truncator HTML methods. Full description

February 3, 2026 - CVE 2026-1287Link to this heading

Potential SQL injection in column aliases via control characters. Full description

February 3, 2026 - CVE 2026-1312Link to this heading

Potential SQL injection via QuerySet.order_by and FilteredRelation. Full description

December 2, 2025 - CVE 2025-13372Link to this heading

Potential SQL injection in FilteredRelation column aliases on PostgreSQL. Full description

December 2, 2025 - CVE 2025-64460Link to this heading

Potential denial-of-service vulnerability in XML serializer text extraction. Full description

November 5, 2025 - CVE 2025-64458Link to this heading

Potential denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows. Full description

November 5, 2025 - CVE 2025-64459Link to this heading

Potential SQL injection via _connector keyword argument in QuerySet and Q objects. Full description

October 1, 2025 - CVE 2025-59681Link to this heading

Potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() on MySQL and MariaDB. Full description

October 1, 2025 - CVE 2025-59682Link to this heading

Potential partial directory-traversal via archive.extract(). Full description

September 3, 2025 - CVE 2025-57833Link to this heading

Potential SQL injection in FilteredRelation column aliases. Full description

June 4, 2025 - CVE 2025-48432Link to this heading

Potential log injection via unescaped request path. Full description

There was an additional hardening with new patch releases published on June 10, 2025. Full description

May 7, 2025 - CVE 2025-32873Link to this heading

Denial-of-service possibility in strip_tags(). Full description

March 6, 2025 - CVE 2025-26699Link to this heading

Potential denial-of-service in django.utils.text.wrap(). Full description

January 14, 2025 - CVE 2024-56374Link to this heading

Potential denial-of-service vulnerability in IPv6 validation. Full description

December 4, 2024 - CVE 2024-53907Link to this heading

Potential denial-of-service in django.utils.html.strip_tags(). Full description

December 4, 2024 - CVE 2024-53908Link to this heading

Potential SQL injection in HasKey(lhs, rhs) on Oracle. Full description

September 3, 2024 - CVE 2024-45231Link to this heading

Potential user email enumeration via response status on password reset. Full description

September 3, 2024 - CVE 2024-45230Link to this heading

Potential denial-of-service vulnerability in django.utils.html.urlize(). Full description

August 6, 2024 - CVE 2024-42005Link to this heading

Potential SQL injection in QuerySet.values() and values_list(). Full description

August 6, 2024 - CVE 2024-41991Link to this heading

Potential denial-of-service vulnerability in django.utils.html.urlize() and AdminURLFieldWidget. Full description

August 6, 2024 - CVE 2024-41990Link to this heading

Potential denial-of-service vulnerability in django.utils.html.urlize(). Full description

August 6, 2024 - CVE 2024-41989Link to this heading

Potential memory exhaustion in django.utils.numberformat.floatformat(). Full description

July 9, 2024 - CVE 2024-39614Link to this heading

Potential denial-of-service in django.utils.translation.get_supported_language_variant(). Full description

July 9, 2024 - CVE 2024-39330Link to this heading

Potential directory-traversal in django.core.files.storage.Storage.save(). Full description

July 9, 2024 - CVE 2024-39329Link to this heading

Username enumeration through timing difference for users with unusable passwords. Full description

July 9, 2024 - CVE 2024-38875Link to this heading

Potential denial-of-service in django.utils.html.urlize(). Full description

March 4, 2024 - CVE 2024-27351Link to this heading

Potential regular expression denial-of-service in django.utils.text.Truncator.words(). Full description

February 6, 2024 - CVE 2024-24680Link to this heading

Potential denial-of-service in intcomma template filter. Full description

2023 年 11 月 1 日 - CVE 2023-46695Link to this heading

关于 Windows 平台上的 UsernameField 存在潜在的拒绝服务漏洞。详细信息请查看 完整描述

2023 年 10 月 4 日 - CVE 2023-43665Link to this heading

django.utils.text.Truncator 中存在拒绝服务可能性。详细信息请查看 完整描述

2023 年 9 月 4 日 - CVE 2023-41164Link to this heading

django.utils.encoding.uri_to_iri() 存在潜在的拒绝服务漏洞。详细信息请查看 完整描述

2023 年 7 月 3 日 - CVE 2023-36053Link to this heading

EmailValidatorURLValidator 存在潜在的正则表达式拒绝服务漏洞。详细信息请查看 完整描述

2023 年 5 月 3 日 - CVE 2023-31047Link to this heading

上传多个文件使用一个表单字段时存在潜在的验证绕过漏洞。详细信息请查看 完整描述

2023 年 2 月 14 日 - CVE 2023-24580Link to this heading

文件上传中存在潜在的拒绝服务漏洞。详细信息请查看 完整描述

2023 年 2 月 1 日 - CVE 2023-23969Link to this heading

通过 Accept-Language 标头存在潜在的拒绝服务漏洞。详细信息请查看 完整描述

2022 年 10 月 4 日 - CVE 2022-41323Link to this heading

国际化 URL 存在潜在的拒绝服务漏洞。详细信息请查看 完整描述

2022 年 8 月 3 日 - CVE 2022-36359Link to this heading

FileResponse 中存在潜在的反射式文件下载漏洞。详细信息请查看 完整描述

2022 年 7 月 4 日 - CVE 2022-34265Link to this heading

通过 Trunc(kind)Extract(lookup_name) 参数存在潜在的 SQL 注入漏洞。详细信息请查看 完整描述

2022 年 4 月 11 日 - CVE 2022-28346Link to this heading

QuerySet.annotate(), aggregate()extra() 中存在潜在的 SQL 注入漏洞。详细信息请查看 完整描述

2022 年 4 月 11 日 - CVE 2022-28347Link to this heading

通过 PostgreSQL 上的 QuerySet.explain(**options) 存在潜在的 SQL 注入漏洞。详细信息请查看 完整描述

2022 年 2 月 1 日 - CVE 2022-22818Link to this heading

可能通过 {% debug %} 模板标签存在跨站脚本攻击(XSS)漏洞。详细信息请查看 完整描述

受影响的版本Link to this heading

2022 年 2 月 1 日 - CVE 2022-23833Link to this heading

文件上传中存在拒绝服务可能性。详细信息请查看 完整描述

受影响的版本Link to this heading

2022 年 1 月 4 日 - CVE 2021-45452Link to this heading

通过 Storage.save() 存在潜在的目录遍历漏洞。详细信息请查看 完整描述

受影响的版本Link to this heading

2022 年 1 月 4 日 - CVE 2021-45116Link to this heading

dictsort 模板过滤器存在潜在的信息泄露漏洞。详细信息请查看 完整描述

受影响的版本Link to this heading

2022 年 1 月 4 日 - CVE 2021-45115Link to this heading

UserAttributeSimilarityValidator 存在拒绝服务可能性。详细信息请查看 完整描述

受影响的版本Link to this heading

2021 年 12 月 7 日 - CVE 2021-44420Link to this heading

存在潜在的绕过基于 URL 路径的上游访问控制漏洞。详细信息请查看 完整描述

受影响的版本Link to this heading

2021 年 7 月 1 日 - CVE 2021-35042Link to this heading

潜在的 SQL 注入,通过未检验的 QuerySet.order_by() 输入。完整描述

受影响的版本Link to this heading

2021 年 6 月 2 日 - CVE 2021-33203Link to this heading

可能通过 admindocs 进行目录遍历。完整描述

受影响的版本Link to this heading

2021 年 6 月 2 日 - CVE 2021-33571Link to this heading

由于验证器接受 IPv4 地址中的前导零,因此可能出现不确定的 SSRF、RFI 和 LFI 攻击。完整描述

受影响的版本Link to this heading

2021 年 5 月 6 日 - CVE 2021-32052Link to this heading

由于 URLValidator 在 Python 3.9.5+ 上接受输入中的换行符,存在标头注入可能性。详细信息请查看 完整描述

受影响的版本Link to this heading

2021 年 5 月 4 日 - CVE 2021-31542Link to this heading

通过上传的文件进行潜在的目录遍历。完整描述

受影响的版本Link to this heading

2021 年 4 月 6 日 - CVE 2021-28658Link to this heading

通过上传的文件进行潜在的目录遍历。完整描述

受影响的版本Link to this heading

2021 年 2 月 19 日 - CVE 2021-23336Link to this heading

通过 django.utils.http.limited_parse_qsl() 进行的网络缓存中毒。完整描述

受影响的版本Link to this heading

2021 年 2 月 1 日 - CVE 2021-3281Link to this heading

通过 archive.extract() 进行潜在的目录遍历。完整说明

受影响的版本Link to this heading

2020 年 9 月 1 日 - CVE 2020-24584Link to this heading

在 Python 3.7+ 上,文件系统缓存的中间层目录的权限升级。完整说明

受影响的版本Link to this heading

2020 年 9 月 1 日 - CVE 2020-24583Link to this heading

在 Python 3.7+ 上,中间层目录的权限不正确。完整说明

受影响的版本Link to this heading

2020 年 6 月 3 日 - CVE 2020-13596Link to this heading

可能通过管理 ForeignKeyRawIdWidget 进行 XSS。完整说明

受影响的版本Link to this heading

2020 年 6 月 3 日 - CVE 2020-13254Link to this heading

通过畸形的 memcached 密钥可能造成数据泄露。完整说明

受影响的版本Link to this heading

2020 年 3 月 4 日 - CVE 2020-9402Link to this heading

针对 Oracle 数据库, 通过 GIS 函数和聚合函数中的 tolerance 参数带来的潜在 SQL 注入。完整说明

受影响的版本Link to this heading

2020 年 2 月 3 日 - CVE 2020-7471Link to this heading

通过 StringAgg(delimiter) 带来的潜在 SQL 注入。 完整说明

受影响的版本Link to this heading

2019 年 12 月 18 日 - CVE 2019-19844Link to this heading

通过密码重置表单带来的潜在账户劫持。完整说明

受影响的版本Link to this heading

2019 年 12 月 2 日 - CVE 2019-19118Link to this heading

在 Django 管理中的特权提升。完整说明

受影响的版本Link to this heading

2019 年 8 月 1 日 - CVE 2019-14235Link to this heading

django.utils.encoding.uri_to_iri() 函数中潜在的内存耗尽。 完整说明

受影响的版本Link to this heading

2019 年 8 月 1 日 - CVE 2019-14234Link to this heading

针对 JSONFieldHStoreField 在键和索引查询时带来的潜在 SQL 注入。 完整说明

受影响的版本Link to this heading

2019 年 8 月 1 日 - CVE 2019-14233Link to this heading

存在于 strip_tags() 函数的拒绝服务攻击。完整说明

受影响的版本Link to this heading

2019 年 8 月 1 日 - CVE 2019-14232Link to this heading

存在于 django.utils.text.Truncator 的拒绝服务攻击。完整说明

受影响的版本Link to this heading

2019 年 7 月 1 日 - CVE 2019-12781Link to this heading

通过 HTTPS 连接反向代理的 HTTP 检测不正确。。完整说明

受影响的版本Link to this heading

2019 年 6 月 3 日 - CVE 2019-12308Link to this heading

AdminURLFieldWidget 生成的 “Current URL” 连接引起的跨站脚本漏洞。完整说明

受影响的版本Link to this heading

2019 年 6 月 3 日 - CVE 2019-11358Link to this heading

捆绑 jQuery 的原型污染。完整说明

受影响的版本Link to this heading

2019 年 2 月 11 日 - CVE 2019-6975Link to this heading

django.utils.numberformat.format() 中内存耗尽。完整说明

受影响的版本Link to this heading

2019 年 1 月 4 日 - CVE 2019-3498Link to this heading

默认 404 页面存在内容欺骗的可能。完整说明

受影响的版本Link to this heading

2018 年 10 月 1 日 - CVE 2018-16984Link to this heading

密码哈希值披露给了 “只看” 的管理员用户。完整说明

受影响的版本Link to this heading

2018 年 8 月 1 日 - CVE 2018-14574Link to this heading

CommonMiddleware 中开放重定向的可能性。完整说明

受影响的版本Link to this heading

2018 年 3 月 6 日 - CVE 2018-7537Link to this heading

truncatechars_htmltruncatewords_html 模板过滤器中存在拒绝服务的可能性。完整说明

受影响的版本Link to this heading

2018 年 3 月 6 日 - CVE 2018-7536Link to this heading

urlizeurlizetrunc 模板过滤器中存在拒绝服务的可能性。完整说明

受影响的版本Link to this heading

2018 年 2 月 1 日 - CVE 2018-6188Link to this heading

AuthenticationForm 中的信息泄露。完整说明

受影响的版本Link to this heading

2017 年 9 月 5 日 - CVE 2017-12794Link to this heading

在技术 500 调试页面的回溯部分可能存在 XSS。完整说明

受影响的版本Link to this heading

2017 年 4 月 4 日 - CVE 2017-7234Link to this heading

django.views.static.service() 中的开放重定向漏洞。完整说明

受影响的版本Link to this heading

2017 年 4 月 4 日 - CVE 2017-7233Link to this heading

通过用户提供的数字重定向 URL 打开重定向和可能的 XSS 攻击。完整说明

受影响的版本Link to this heading

2016 年 11 月 1 日 - CVE 2016-9014Link to this heading

DEBUG=Tr 时,DNS 重绑定漏洞。完整说明

受影响的版本Link to this heading

2016 年 11 月 1 日 - CVE 2016-9013Link to this heading

在 Oracle 上运行测试时创建的带有硬编码密码的用户。完整说明

受影响的版本Link to this heading

2016 年 9 月 26 日 - CVE 2016-7401Link to this heading

在有 Google Analytics 的网站上绕过 CSRF 保护。完整说明

受影响的版本Link to this heading

2016 年 7 月 18 日 - CVE 2016-6186Link to this heading

管理员的添加/更改相关弹窗中的 XSS。完整说明

受影响的版本Link to this heading

2016 年 3 月 1 日 - CVE 2016-2513Link to this heading

通过时间差对密码哈希工作因子升级进行用户枚举。完整说明

受影响的版本Link to this heading

2016 年 3 月 1 日 - CVE 2016-2512Link to this heading

通过用户提供的包含基本认证的重定向 URL 进行恶意重定向和可能的 XSS 攻击。完整说明

受影响的版本Link to this heading

2016 年 2 月 1 日 - CVE 2016-2048Link to this heading

拥有 “变更” 而非 “添加” 权限的用户可以用 “保存为 True” 为 ModelAdmin 创建对象。完整说明

受影响的版本Link to this heading

2015 年 11 月 24 日 - CVE 2015-8213Link to this heading

date 模板过滤器存在设置泄漏可能性。详细信息请查看 完整描述

受影响的版本Link to this heading

2015 年 8 月 18 日 - CVE 2015-5963 / CVE 2015-5964Link to this heading

通过填充会话存储,存在 logout() 视图的拒绝服务可能性。详细信息请查看 完整描述

受影响的版本Link to this heading

2015 年 7 月 8 日 - CVE 2015-5145Link to this heading

URL 验证中存在拒绝服务可能性。详细信息请查看 完整描述

受影响的版本Link to this heading

2015 年 7 月 8 日 - CVE 2015-5144Link to this heading

由于验证器接受输入中的换行符,存在标头注入可能性。详细信息请查看 完整描述

受影响的版本Link to this heading

2015 年 7 月 8 日 - CVE 2015-5143Link to this heading

通过填充会话存储存在拒绝服务可能性。详细信息请查看 完整描述

受影响的版本Link to this heading

2015 年 5 月 20 日 - CVE 2015-3982Link to this heading

修复了 cached_db 后端中的会话刷新问题。详细信息请查看 完整描述

受影响的版本Link to this heading

2015 年 3 月 18 日 - CVE 2015-2317Link to this heading

通过用户提供的重定向 URL 缓解了可能的跨站脚本(XSS)攻击。详细信息请查看 完整描述

受影响的版本Link to this heading

2015年 3 月 18 日 - CVE 2015-2316Link to this heading

使用 strip_tags() 存在拒绝服务可能性。详细信息请查看 完整描述

受影响的版本Link to this heading

2015 年 3 月9 日 - CVE 2015-2241Link to this heading

通过 ModelAdmin.readonly_fields 中的属性存在跨站脚本(XSS)攻击漏洞。详细信息请查看 完整描述

受影响的版本Link to this heading

2015 年 1 月 13 日 - CVE 2015-0222Link to this heading

使用 ModelMultipleChoiceField 存在数据库拒绝服务漏洞。详细信息请查看 完整描述

受影响的版本Link to this heading

2015 年 1 月 13 日 - CVE 2015-0221Link to this heading

存在针对 django.views.static.serve() 的拒绝服务攻击漏洞。详细信息请查看 完整描述

受影响的版本Link to this heading

2015 年 1 月 13 日 - CVE 2015-0220Link to this heading

通过用户提供的重定向 URL 缓解了可能的跨站脚本(XSS)攻击。详细信息请查看 完整描述

受影响的版本Link to this heading

2015 年 1 月 13 日 - CVE 2015-0219Link to this heading

通过下划线/短横线混合欺骗 WSGI 标头。完整描述

受影响的版本Link to this heading

2014 年 8 月 20 日 - CVE 2014-0483Link to this heading

在管理员中通过查询字符串操纵导致数据泄漏。完整描述

受影响的版本Link to this heading

2014 年 8 月 20 日 - CVE 2014-0482Link to this heading

RemoteUserMiddleware 会话劫持。完整描述

受影响的版本Link to this heading

2014 年 8 月 20 日 - CVE 2014-0481Link to this heading

文件上传拒绝服务。完整描述

受影响的版本Link to this heading

2014 年 8 月 20 日 - CVE 2014-0480Link to this heading

reverse() 可以生成指向其他主机的 URL。完整描述

受影响的版本Link to this heading

2014 年 5 月 18 日 - CVE 2014-3730Link to this heading

来自用户输入的格式不正确的 URL 被错误验证。完整描述

受影响的版本Link to this heading

2014 年 5 月 18 日 - CVE 2014-1418Link to this heading

缓存可能允许存储和提供私人数据。完整描述

受影响的版本Link to this heading

2014 年 4 月 21 日 - CVE 2014-0474Link to this heading

MySQL 类型转换导致意外的查询结果。完整描述

受影响的版本Link to this heading

2014 年 4 月 21 日 - CVE 2014-0473Link to this heading

匿名页面的缓存可能会显示 CSRF 令牌。完整描述

受影响的版本Link to this heading

2014 年 4 月 21 日 - CVE 2014-0472Link to this heading

使用 reverse() 导致意外的代码执行。完整描述

受影响的版本Link to this heading

2013 年 9 月 14 日 - CVE 2013-1443Link to this heading

通过大型密码进行拒绝服务攻击。完整描述

受影响的版本Link to this heading

2013 年 9 月 10 日 - CVE 2013-4315Link to this heading

通过 ssi 模板标签进行目录遍历。完整描述

受影响的版本Link to this heading

2013 年 8 月 13 日 - CVE 2013-6044Link to this heading

可能通过未经验证的 URL 重定向方案进行跨站脚本(XSS)攻击。完整描述

受影响的版本Link to this heading

2013 年 8 月 13 日 - CVE 2013-4249Link to this heading

通过管理员信任的 URLField 值进行跨站脚本(XSS)攻击。完整描述

受影响的版本Link to this heading

2013 年 1 月 19 日 - CVE 2013-0306Link to this heading

通过 formset 的 max_num 绕过进行拒绝服务攻击。完整描述

受影响的版本Link to this heading

2013 年 1 月 19 日 - CVE 2013-0305Link to this heading

通过管理员历史记录日志泄露信息。完整描述

受影响的版本Link to this heading

2013 年 1 月 19 日 - CVE 2013-1664 / CVE 2013-1665Link to this heading

针对 Python XML 库的实体攻击。完整描述

受影响的版本Link to this heading

2013 年 2 月 19 日 - 无 CVELink to this heading

Host 头处理的额外加固。完整描述

受影响的版本Link to this heading

2012 年 12 月 10 日 - 无 CVE 2Link to this heading

对重定向验证的额外加固。完整描述

受影响的版本Link to this heading

2012 年 12 月 10 日 - 无 CVE 1Link to this heading

Host 头处理的额外加固。完整描述

受影响的版本Link to this heading

2012 年 10 月 17 日 - CVE 2012-4520Link to this heading

Host 头部污染。完整描述

受影响的版本Link to this heading

2012 年 7 月 30 日 - CVE 2012-3444Link to this heading

通过大型图像文件进行拒绝服务攻击。完整描述

受影响的版本Link to this heading

2012 年 7 月 30 日 - CVE 2012-3443Link to this heading

通过压缩的图像文件进行拒绝服务攻击。完整描述

受影响的版本Link to this heading

2012 年 7 月 30 日 - CVE 2012-3442Link to this heading

通过未能验证重定向方案进行跨站脚本(XSS)攻击。完整描述

受影响的版本Link to this heading

2011 年 9 月 9 日 - CVE 2011-4140Link to this heading

潜在的 CSRF(跨站请求伪造)攻击通过 Host 头部。完整描述

受影响的版本Link to this heading

此通知仅为提醒,因此没有发布补丁。

  • Django 1.2

  • Django 1.3

2011 年9月9日 - CVE 2011-4139Link to this heading

Host 头部缓存污染。完整描述

受影响的版本Link to this heading

2011 年9月9日 - CVE 2011-4138Link to this heading

通过 URLField.verify_exists 存在信息泄露/任意请求发出。完整描述

受影响的版本Link to this heading

2011 年 9 月 9 日 - CVE 2011-4137Link to this heading

通过 URLField.verify_exists 进行拒绝服务攻击。完整描述

受影响的版本Link to this heading

2011 年9月9日 - CVE 2011-4136Link to this heading

在使用内存缓存支持的会话时进行会话操纵。完整描述

受影响的版本Link to this heading

2011 年 2 月 8 日 - CVE 2011-0698Link to this heading

通过不正确的路径分隔符处理在 Windows 上进行目录遍历。完整描述

受影响的版本Link to this heading

2011 年 2 月 8 日 - CVE 2011-0697Link to this heading

通过未经过滤的上传文件的名称进行跨站脚本(XSS)攻击。完整描述

受影响的版本Link to this heading

2011 年 2 月 8 日 - CVE 2011-0696Link to this heading

通过伪造的 HTTP 头部进行 CSRF 攻击。完整描述

受影响的版本Link to this heading

2010 年 12 月 22 日 - CVE 2010-4535Link to this heading

在密码重置机制中的拒绝服务攻击。完整描述

受影响的版本Link to this heading

2010 年 12 月 22 日 - CVE 2010-4534Link to this heading

界面管理中的信息泄漏`完整描述<https://www.djangoproject.com/weblog/2010/dec/22/security/>`__

受影响的版本Link to this heading

2010年9月8日 - CVE 2010-3082Link to this heading

XSS通过信任不安全的cookie值。完整描述<https://www.djangoproject.com/weblog/2010/sep/08/security-release/>`__

受影响的版本Link to this heading

2009 年 10 月 9 日 - CVE 2009-3965Link to this heading

通过缺陷正则表达性能拒绝服务。完整说明

受影响的版本Link to this heading

2009 年 7 月 28 日 - CVE 2009-2659Link to this heading

开发服务器媒体处理程序中的目录遍历。完整说明

受影响的版本Link to this heading

2008 年 9 月 2 日 - CVE 2008-3909Link to this heading

在管理员登录时通过保存 POST 数据进行 CSRF。完整说明

受影响的版本Link to this heading

2008 年 5 月 14 日 - CVE 2008-2302Link to this heading

通过管理员登录重定向进行 XSS。完整说明

受影响的版本Link to this heading

2007 年 10 月 26 日 - CVE 2007-5712Link to this heading

通过任意大的 Accept-Language 头拒绝服务。完整说明

受影响的版本Link to this heading

Django 安全进程之前的问题Link to this heading

有些安全问题是在 Django 还没有正式使用安全流程之前就已经处理好的。对于这些问题,当时可能还没有发布新的版本,可能还没有分配 CVE。

2007 年 1 月 21 日 - CVE 2007-0405Link to this heading

对认证用户进行明显的 “缓存”。完整说明

受影响的版本Link to this heading

2006 年 8 月 16 日 - CVE 2007-0404Link to this heading

翻译框架中的文件名验证问题。完整说明

受影响的版本Link to this heading