Executive brief
A vulnerability was identified in Django, a popular web framework, where certain domain name validation checks failed to block newline characters. If an application uses these validated domain names directly in web responses, an attacker could potentially inject malicious headers into the communication. This could lead to various security issues, such as redirecting users to malicious sites or bypassing certain security controls, though Django's default response handler provides some built-in protection against this specific behavior.
Technical details
A vulnerability exists in Django's DomainNameValidator where it fails to prohibit newline characters in domain names. While Django's CharField typically strips newlines when used in forms, the validator itself does not, potentially allowing malicious input to pass through if used in other contexts. If an application subsequently includes these validated strings in an HTTP response header, it could lead to HTTP header injection (CWE-144). Although Django's HttpResponse class prohibits newlines in headers by default, applications using alternative response methods or manual header construction may be vulnerable. The issue is patched in versions 5.2.16 and 6.0.7.
Affected products
- Django Software Foundation Django 5.2 before 5.2.16, 6.0 before 6.0.7
Timeline
- 2026-07-07: disclosed
- 2026-07-07: patched
- 2026-07-07: advisory
References
- https://docs.djangoproject.com/en/dev/releases/security
- https://groups.google.com/g/django-announce
- https://www.djangoproject.com/weblog/2026/jul/07/security-releases
- https://github.com/django/django/commit/3a720d0d8bf2529253b98968f10ca73daf6d693c
- https://github.com/django/django/commit/a5de13f1491f1dbf2bb0ad9b91570524ebbc8acd