Vulnerabilidades en djangoproject
42 resultadosAnálisis Vexday
Django apresenta 38 vulnerabilidades cadastradas, com 13 publicadas nos últimos 90 dias, indicando atividade contínua de descoberta de falhas. Apenas 2 vulnerabilidades críticas foram identificadas e nenhuma está sendo explorada ativamente (KEV), sugerindo risco moderado no curto prazo. A fraqueza dominante (CWE-770) aponta para problemas de alocação de recursos, recomendando monitoramento de patches e revisão de configurações de limite em ambientes de produção.
CVE-2025-13473MEDIUMUsername enumeration through timing difference in mod_wsgi authentication handlerEPSS 0.8%CVE-2025-48432MEDIUMAn issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escapeEPSS 0.8%CVE-2026-25673HIGHPotential denial-of-service vulnerability in URLField via Unicode normalization on WindowsEPSS 0.7%CVE-2025-59681HIGHAn issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySeEPSS 0.6%CVE-2026-35192LOWSession fixation via public cached pages and SESSION_SAVE_EVERY_REQUESTEPSS 0.5%CVE-2026-4277CRITICALPrivilege abuse in GenericInlineModelAdminEPSS 0.5%CVE-2026-53877MEDIUMHeap buffer over-read in GDALRasterEPSS 0.4%CVE-2026-3902HIGHASGI header spoofing via underscore/hyphen conflationEPSS 0.4%CVE-2026-48588LOWPotential exposure of private data via cached Set-Cookie responseEPSS 0.4%CVE-2026-5766MEDIUMPotential denial-of-service vulnerability in ASGI requests via file upload limit bypassEPSS 0.4%CVE-2026-15920MEDIUMPotential cross-site scripting via URLField values in the adminEPSS 0.4%CVE-2026-35193LOWPotential exposure of private data via missing Vary: Authorization in UpdateCacheMiddlewareEPSS 0.4%CVE-2026-48587LOWPotential exposure of private data via whitespace padding in Vary headerEPSS 0.4%CVE-2026-6907LOWPotential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddlewareEPSS 0.4%CVE-2026-25674LOWPotential incorrect permissions on newly created file system objectsEPSS 0.3%CVE-2026-44545MEDIUMUnbounded WebSocket message and frame sizes can cause unauthenticated remote denial of serviceEPSS 0.3%CVE-2026-53878MEDIUMHeader injection possibility since DomainNameValidator accepted newlines in inputEPSS 0.3%CVE-2026-4292LOWPrivilege abuse in ModelAdmin.list_editableEPSS 0.3%CVE-2026-8404LOWPotential exposure of private data via case-sensitive Cache-Control directives in UpdateCacheMiddlewareEPSS 0.3%CVE-2026-6873LOWSigned cookie salt namespace collision in django.http.HttpRequest.get_signed_cookieEPSS 0.2%