Skip to content
RequestGuard Vulnerabilities
Pricing

Django

A high-level Python web framework that encourages rapid development and clean, pragmatic design.

PyPI latest 6.1.1 BSD-3-Clause

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

6.1.1

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Critical

161 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

161

Django vulnerable to privilege abuse in GenericInlineModelAdmin

Affected range

ECOSYSTEM: introduced 6.0; fixed 6.0.4ECOSYSTEM: introduced 5.2; fixed 5.2.13ECOSYSTEM: introduced 4.2; fixed 4.2.30ECOSYSTEM: introduced 4.2; fixed 4.2.30; introduced 5.2; fixed 5.2.13; introduced 6.0; fixed 6.0.4

Fixed versions: 6.0.4, 5.2.13, 4.2.30

Django vulnerable to SQL injection in column aliases

Affected range

ECOSYSTEM: introduced 4.2; fixed 4.2.25ECOSYSTEM: introduced 5.1; fixed 5.1.13ECOSYSTEM: introduced 5.2; fixed 5.2.7ECOSYSTEM: introduced 4.2; fixed 4.2.25; introduced 5.1; fixed 5.1.13; introduced 5.2; fixed 5.2.7

Fixed versions: 4.2.25, 5.1.13, 5.2.7

Django SQL injection in HasKey(lhs, rhs) on Oracle

Affected range

ECOSYSTEM: introduced 5.0.0; fixed 5.0.10ECOSYSTEM: introduced 5.1.0; fixed 5.1.4ECOSYSTEM: introduced 4.2.0; fixed 4.2.17ECOSYSTEM: introduced 5.1; fixed 5.1.4ECOSYSTEM: introduced 5.0; fixed 5.0.10

Fixed versions: 5.0.10, 5.1.4, 4.2.17

Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.

Affected range

ECOSYSTEM: introduced 5.2a1; fixed 5.2.8ECOSYSTEM: introduced 5.0a1; fixed 5.1.14ECOSYSTEM: introduced 0; fixed 4.2.26ECOSYSTEM: introduced 4.2; fixed 4.2.26; introduced 5.1; fixed 5.1.14; introduced 5.2; fixed 5.2.8

Fixed versions: 5.2.8, 5.1.14, 4.2.26

Django SQL injection vulnerability

Affected range

ECOSYSTEM: introduced 5.0; fixed 5.0.8ECOSYSTEM: introduced 4.2; fixed 4.2.15ECOSYSTEM: introduced 5.0; fixed 5.0.8; introduced 4.2; fixed 4.2.15

Fixed versions: 5.0.8, 4.2.15

Code Injection in Django

Affected range

ECOSYSTEM: introduced 0; fixed 1.4.11ECOSYSTEM: introduced 1.5; fixed 1.5.6ECOSYSTEM: introduced 1.6; fixed 1.6.3ECOSYSTEM: introduced 0; fixed 1.4.11; introduced 1.5; fixed 1.5.6; introduced 1.6; fixed 1.6.3

Fixed versions: 1.4.11, 1.5.6, 1.6.3

Django Vulnerable to MySQL Injection

Affected range

ECOSYSTEM: introduced 0; fixed 1.4.11ECOSYSTEM: introduced 1.5; fixed 1.5.6ECOSYSTEM: introduced 1.6; fixed 1.6.3ECOSYSTEM: introduced 0; fixed 1.4.11; introduced 1.5; fixed 1.5.6; introduced 1.6; fixed 1.6.3

Fixed versions: 1.4.11, 1.5.6, 1.6.3

SQL injection in Django

Affected range

ECOSYSTEM: introduced 0; fixed 1.11.28ECOSYSTEM: introduced 2.0; fixed 2.2.10ECOSYSTEM: introduced 3.0; fixed 3.0.3GIT: introduced 0; fixed eb31d845323618d688ad429479c6dda973056136ECOSYSTEM: introduced 1.11; fixed 1.11.28; introduced 2.2; fixed 2.2.10; introduced 3.0; fixed 3.0.3

Fixed versions: 1.11.28, 2.2.10, 3.0.3, eb31d845323618d688ad429479c6dda973056136

SQL Injection in Django

Affected range

ECOSYSTEM: introduced 1.11a1; fixed 1.11.23ECOSYSTEM: introduced 2.1a1; fixed 2.1.11ECOSYSTEM: introduced 2.2a1; fixed 2.2.4ECOSYSTEM: introduced 2.1; fixed 2.1.11; introduced 1.11; fixed 1.11.23; introduced 2.2; fixed 2.2.4

Fixed versions: 1.11.23, 2.1.11, 2.2.4

SQL Injection in Django

Affected range

ECOSYSTEM: introduced 2.2; fixed 2.2.28ECOSYSTEM: introduced 3.2; fixed 3.2.13ECOSYSTEM: introduced 4.0; fixed 4.0.4ECOSYSTEM: introduced 4.0; fixed 4.0.4; introduced 3.2; fixed 3.2.13; introduced 2.2; fixed 2.2.28

Fixed versions: 2.2.28, 3.2.13, 4.0.4

SQL Injection in Django

Affected range

ECOSYSTEM: introduced 2.2; fixed 2.2.28ECOSYSTEM: introduced 3.2; fixed 3.2.13ECOSYSTEM: introduced 4.0; fixed 4.0.4ECOSYSTEM: introduced 4.0; fixed 4.0.4; introduced 3.2; fixed 3.2.13; introduced 2.2; fixed 2.2.28

Fixed versions: 2.2.28, 3.2.13, 4.0.4

Django bypasses validation when using one form field to upload multiple files

Affected range

ECOSYSTEM: introduced 3.2a1; fixed 3.2.19ECOSYSTEM: introduced 4.0a1; fixed 4.1.9ECOSYSTEM: introduced 4.2a1; fixed 4.2.1ECOSYSTEM: introduced 3.2; fixed 3.2.19; introduced 4.0; fixed 4.1.9; introduced 4.2; fixed 4.2.1

Fixed versions: 3.2.19, 4.1.9, 4.2.1

SQL Injection in Django

Affected range

ECOSYSTEM: introduced 3.2a1; fixed 3.2.5ECOSYSTEM: introduced 3.0a1; fixed 3.1.13ECOSYSTEM: introduced 3.1; fixed 3.1.13; introduced 3.2; fixed 3.2.5

Fixed versions: 3.2.5, 3.1.13

Django `Trunc()` and `Extract()` database functions vulnerable to SQL Injection

Affected range

ECOSYSTEM: introduced 3.2a1; fixed 3.2.14ECOSYSTEM: introduced 4.0a1; fixed 4.0.6ECOSYSTEM: introduced 3.2; fixed 3.2.14; introduced 4.0; fixed 4.0.6

Fixed versions: 3.2.14, 4.0.6

Django Vulnerable to Cache Poisoning

Affected range

ECOSYSTEM: introduced 1.4; fixed 1.4.13ECOSYSTEM: introduced 1.5; fixed 1.5.8ECOSYSTEM: introduced 1.6; fixed 1.6.5ECOSYSTEM: introduced 1.7a1; fixed 1.7b4ECOSYSTEM: introduced 1.4; fixed 1.4.13; introduced 1.5; fixed 1.5.8; introduced 1.6; fixed 1.6.5; introduced 1.7a0; fixed 1.7b4

Fixed versions: 1.4.13, 1.5.8, 1.6.5, 1.7b4

Django DNS Rebinding Vulnerability

Affected range

ECOSYSTEM: introduced 1.8a1; fixed 1.8.16ECOSYSTEM: introduced 1.9a1; fixed 1.9.11ECOSYSTEM: introduced 1.10a1; fixed 1.10.3ECOSYSTEM: introduced 0; fixed 1.8.16; introduced 1.9; fixed 1.9.11; introduced 1.10; fixed 1.10.3

Fixed versions: 1.8.16, 1.9.11, 1.10.3

Django Allows Redirect via Data URL

Affected range

ECOSYSTEM: introduced 0; fixed 1.3.2ECOSYSTEM: introduced 1.4; fixed 1.4.1ECOSYSTEM: introduced 0; fixed 1.3.2; introduced 1.4; fixed 1.4.1

Fixed versions: 1.3.2, 1.4.1

Django Potential account hijack via password reset form

Affected range

ECOSYSTEM: introduced 0; fixed 1.11.27ECOSYSTEM: introduced 2.0; fixed 2.2.9ECOSYSTEM: introduced 3.0; fixed 3.0.1ECOSYSTEM: introduced 0; fixed 1.11.27; introduced 2.2; fixed 2.2.9

Fixed versions: 1.11.27, 2.2.9, 3.0.1

Django user with hardcoded password created when running tests on Oracle

Affected range

ECOSYSTEM: introduced 1.10a1; fixed 1.10.3ECOSYSTEM: introduced 1.9a1; fixed 1.9.11ECOSYSTEM: introduced 1.8a1; fixed 1.8.16ECOSYSTEM: introduced 1.8; fixed 1.8.16; introduced 1.9; fixed 1.9.11; introduced 1.10; fixed 1.10.3

Fixed versions: 1.10.3, 1.9.11, 1.8.16

Directory traversal in Django

Affected range

ECOSYSTEM: introduced 1.1; fixed 1.1.4ECOSYSTEM: introduced 1.2; fixed 1.2.5ECOSYSTEM: introduced 1.1; fixed 1.1.4; introduced 1.2; fixed 1.2.5

Fixed versions: 1.1.4, 1.2.5

Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit

Affected range

ECOSYSTEM: introduced 6.0; fixed 6.0.4ECOSYSTEM: introduced 5.2; fixed 5.2.13ECOSYSTEM: introduced 4.2; fixed 4.2.30ECOSYSTEM: introduced 4.2; fixed 4.2.30; introduced 5.2; fixed 5.2.13; introduced 6.0; fixed 6.0.4

Fixed versions: 6.0.4, 5.2.13, 4.2.30

Django has Inefficient Algorithmic Complexity

Affected range

ECOSYSTEM: introduced 6.0a1; fixed 6.0.2ECOSYSTEM: introduced 5.2a1; fixed 5.2.11ECOSYSTEM: introduced 4.2a1; fixed 4.2.28ECOSYSTEM: introduced 4.2; fixed 4.2.28; introduced 5.2; fixed 5.2.11; introduced 6.0; fixed 6.0.2

Fixed versions: 6.0.2, 5.2.11, 4.2.28

Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

Affected range

ECOSYSTEM: introduced 5.2a1; fixed 5.2.8ECOSYSTEM: introduced 5.0a1; fixed 5.1.14ECOSYSTEM: introduced 0; fixed 4.2.26ECOSYSTEM: introduced 4.2; fixed 4.2.26; introduced 5.1; fixed 5.1.14; introduced 5.2; fixed 5.2.8

Fixed versions: 5.2.8, 5.1.14, 4.2.26

Django denial-of-service in django.utils.html.strip_tags()

Affected range

ECOSYSTEM: introduced 5.1.0; fixed 5.1.4ECOSYSTEM: introduced 4.2.0; fixed 4.2.17ECOSYSTEM: introduced 5.0.0; fixed 5.0.10ECOSYSTEM: introduced 5.1; fixed 5.1.4ECOSYSTEM: introduced 5.0; fixed 5.0.10

Fixed versions: 5.1.4, 4.2.17, 5.0.10

Django vulnerable to ASGI header spoofing via underscore/hyphen conflation

Affected range

ECOSYSTEM: introduced 6.0; fixed 6.0.4ECOSYSTEM: introduced 5.2; fixed 5.2.13ECOSYSTEM: introduced 4.2; fixed 4.2.30ECOSYSTEM: introduced 4.2; fixed 4.2.30; introduced 5.2; fixed 5.2.13; introduced 6.0; fixed 6.0.4

Fixed versions: 6.0.4, 5.2.13, 4.2.30

Show 75 more advisories
GHSA-8p8v-wh79-9r56 Django vulnerable to Uncontrolled Resource Consumption
GHSA-mwm9-4648-f68q Django has an SQL Injection issue
GHSA-gvg8-93h5-g6qq Django has an SQL Injection issue
GHSA-4rrr-2h4v-f3j9 Django has Inefficient Algorithmic Complexity
GHSA-vrcr-9hj9-jcg6 Django is vulnerable to DoS via XML serializer text extraction
GHSA-6w2r-r2m5-xq5w Django is subject to SQL injection through its column aliases
GHSA-qg2p-9jwr-mmqf Django vulnerable to Denial of Service
GHSA-f6f8-9mx6-9mx2 Django vulnerable to Denial of Service
GHSA-9jmf-237g-qf46 Django Path Traversal vulnerability
GHSA-xxj9-f6rv-m3x4 Django denial-of-service attack in the intcomma template filter
GHSA-3gh2-xw74-jmcw SQL injection in Django
GHSA-qc99-g3wm-hgxr Django Arbitrary Code Execution
GHSA-7wph-fc4w-wqp2 Improper date handling in Django
GHSA-fwr5-q9rx-294f Improper query string handling in Django
GHSA-5j2h-h5hg-3wf8 Cross-site request forgery in Django
GHSA-8x94-hmjh-97hq Django vulnerable to Reflected File Download attack
GHSA-h8gc-pgj2-vjm3 Django Denial-of-service in django.utils.text.Truncator
GHSA-jh3w-4vvf-mjgr Django has regular expression denial of service vulnerability in EmailValidator/URLValidator
GHSA-89hj-xfx5-7q66 Django Reuses Cached CSRF Token
GHSA-2hrw-hx67-34x6 Resource exhaustion in Django
GHSA-8c5j-9r9f-c6w8 Information disclosure in Django
GHSA-wh4h-v3f2-r2pp Uncontrolled Memory Consumption in Django
GHSA-q5qw-4364-5hhm Django Vulnerable to HTTP Response Splitting Attack
GHSA-jhjg-w2cp-5j44 Django DoS in django.views.static.serve
GHSA-vq3h-3q7v-9prw Django Allows Open Redirects
GHSA-296w-6qhq-gf92 Django denial of service via file upload naming
GHSA-f7cm-ccfp-3q4r Django Incorrectly Validates URLs
GHSA-pgxh-wfw4-jx2v Django denial of service via empty session record creation
GHSA-x38m-486c-2wr9 Denial-of-service possibility in logout() view by filling session store
GHSA-crhm-qpjc-cm64 Django CSRF Protection Bypass
GHSA-46x4-9jmv-jc8p Django Access Restrictions Bypass
GHSA-wpjr-j57x-wxfw Data leakage via cache key collision in Django
GHSA-fr28-569j-53c4 Django Incorrect Default Permissions
GHSA-v6rh-hp5x-86rv Potential bypass of an upstream access control based on URL paths in Django
GHSA-hvmf-r92r-27hr Django allows unintended model editing
GHSA-337x-4q8g-prc5 Improper Input Validation in Django
GHSA-9v8h-57gv-qch6 Django vulnerable to Denial of Service via i18n middleware component
GHSA-h5jv-4p7w-64jg Django Denial-of-service in strip_tags()
GHSA-v9qg-3j8p-r63v Uncontrolled Recursion in Django
GHSA-c4qh-4vgv-qc6g Django Denial-of-service in django.utils.text.Truncator
GHSA-53qw-q765-4fww Denial-of-service in Django
GHSA-p99v-5w3c-jqq9 Django Access Control Bypass possibly leading to SSRF, RFI, and LFI attacks
GHSA-qmf9-6jqf-j8fq Django potential denial of service vulnerability in UsernameField on Windows
GHSA-qrw5-5h28-6cmg Django denial-of-service vulnerability in internationalized URLs
GHSA-q2jf-h9jm-m7p4 Django contains Uncontrolled Resource Consumption via cached header
GHSA-6cw3-g6wv-c2xv Infinite Loop in Django
GHSA-rxjp-mfm9-w4wr Path Traversal in Django
GHSA-rf4j-j272-fj86 Django vulnerable to information leakage in AuthenticationForm
GHSA-m6gj-h9gm-gw44 Django Incorrect Default Permissions
GHSA-6g95-x6cj-mg4v Django database denial-of-service with ModelMultipleChoiceField
GHSA-vjjp-9r83-22rc Django Directory Traversal via ssi template tag
GHSA-2655-q453-22f9 Django Allows Arbitrary URL Generation
GHSA-pw27-w7w4-9qc7 Django XSS Vulnerability
GHSA-cqf7-ff9h-7967 Django ReDoS in validators.URLValidator
GHSA-j3j3-jrfh-cm2w Django Denial-of-service possibility with strip_tags
GHSA-4c42-4rxm-x6qf Django Denial of Service Vulnerability in the authentication framework
GHSA-h582-2pch-3xv3 Django Denial-of-service by filling session store
GHSA-6wgp-fwfm-mxp3 Django allows user sessions hijacking via an empty string in the session key
GHSA-59w8-4wm2-4xw8 Django Image Field Vulnerable to Image Decompression Bombs
GHSA-wxg3-mfph-qg9w Django Might Allow CSRF Requests via URL Verification
GHSA-rm2j-x595-q9cj Django Vulnerable to Cache Poisoning
GHSA-3jqw-crqj-w8qw Denial of service in django
GHSA-r5cj-wv24-92p5 Django cross-site request forgery (CSRF) vulnerability
GHSA-h95j-h2rv-qrg4 Django Cross-Site Request Forgery vulnerability
GHSA-9xg7-gg9m-rmq9 Django Admin Media Handler Vulnerable to Directory Traversal
GHSA-p6m5-h7pp-v2x5 Django Regex Algorithmic Complexity Causes Denial of Service
GHSA-5h2q-4hrp-v9rr Django vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer
GHSA-crhf-3pfg-w68w Django: GDALRaster may over-read heap memory when constructed from bytes
GHSA-8qcx-xf44-272x Django: DomainNameValidator permits newline characters that may enable HTTP header injection
GHSA-3h9f-r86x-qvjx Django: cache middleware may expose private responses when unrelated request cookies are present
GHSA-w26r-rmm8-9c29 Django has an Improper Handling of Length Parameter Inconsistency
GHSA-rqw2-ghq9-44m7 Django is vulnerable to SQL injection in column aliases
GHSA-8j24-cjrq-gr2m Django has a denial-of-service possibility in strip_tags()
GHSA-h7pc-vwp9-298g Django: signed cookies are vulnerable to salt namespace collisions
GHSA-923m-gv2p-w5qp Django: has_vary_header may expose cached responses when Vary values contain whitespace