Junglewise Threat Intelligence

CVE-2026-7666: Django cleartext email transmission in SMTP EmailBackend

CVE-2026-7666 · Severity: medium · CVSS 4 · Published 2026-06-03

Technologies: Django (PyPI), Django Software Foundation Django. Vendors: PyPI, Django Software Foundation.

Executive brief

Django, a popular web framework, contains a flaw in how it handles secure email connections. When configured to ignore errors, the system may continue to send emails over an unencrypted connection if the initial security handshake fails. This could allow an attacker positioned on the network to intercept and read sensitive email content.

Technical details

The vulnerability exists in django.core.mail.backends.smtp.EmailBackend. When the 'fail_silently' parameter is set to True, the backend does not properly terminate the connection if the STARTTLS handshake fails. Instead, it may proceed to transmit email data over the existing unencrypted socket. An on-path attacker (Man-in-the-Middle) can trigger a handshake failure to force the transmission of sensitive data in cleartext. The issue is fixed in Django versions 5.2.15 and 6.0.6. Older, unsupported versions like 3.2, 4.1, and 5.0 may also be affected but were not explicitly tested.

Affected products

  • Django Software Foundation Django >= 5.2, < 5.2.15; >= 6.0, < 6.0.6

Timeline

  • 2026-06-03: disclosed
  • 2026-06-03: advisory
  • 2026-06-03: patched

References

Related threats