Vendor
Django Software Foundation vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 35 vulnerabilities in Django Software Foundation: 0 in the last 7 days and 6 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-73229, was published on 1 September 2026.
- Last 7 days
- 0
- Last 90 days
- 6
- Critical, all time
- 1
- Exploited in the wild
- 0
About Django Software Foundation
A non-profit organization that supports and maintains the Django web framework.
Latest Django Software Foundation vulnerabilities
- CVE-2026-73229: Django REST framework AdminRenderer permission bypass information disclosuremediumCVSS 4.3EPSS 0.4%
- CVE-2026-73228: Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in…mediumCVSS 5.3EPSS 0.6%
- CVE-2026-15830: Django GeoDjango unbounded recursion denial of servicemediumCVSS 5.3EPSS 0.8%
- CVE-2026-53878: Django DomainNameValidator header injection via newline charactersmediumCVSS 6.1EPSS 0.3%
- CVE-2026-53877: Django GDALRaster heap buffer over-read in GIS componentmediumCVSS 4.8EPSS 0.4%
- CVE-2026-48588: Django private data exposure in UpdateCacheMiddleware cachinglowCVSS 3.1EPSS 0.4%
- CVE-2026-8404: Django UpdateCacheMiddleware information disclosure via case-sensitive headerslowCVSS 3.1EPSS 0.4%
- CVE-2026-7666: Django cleartext email transmission in SMTP EmailBackendmediumCVSS 4EPSS 0.2%
- CVE-2026-6873: Django salt namespace collision in get_signed_cookielowCVSS 3.1EPSS 0.3%
- CVE-2026-48587: Django information disclosure via whitespace padding in Vary headerlowCVSS 3.1EPSS 0.4%
- CVE-2026-44546: Django Daphne header injection in WebSocket handshakelowCVSS 3.7EPSS 0.3%
- CVE-2026-44545: Django Daphne denial of service via unlimited WebSocket payload sizemediumCVSS 5.3EPSS 0.6%
- CVE-2026-35193: Django UpdateCacheMiddleware information disclosure via missing Vary headermediumCVSS 4EPSS 0.4%
- CVE-2026-5766: Django Improper Handling of Length Parameter Inconsistency in ASGI requestsmediumCVSS 5.3EPSS 0.5%
- CVE-2026-6907: Django incorrect caching of sensitive information in UpdateCacheMiddlewaremediumCVSS 4.3EPSS 0.4%
- CVE-2026-35192: Django session leakage via public cached pagesmediumCVSS 4EPSS 0.7%
- CVE-2026-4292: Django privilege abuse in ModelAdmin.list_editablelowCVSS 3.1EPSS 0.4%
- CVE-2026-4277: Django missing authorization in GenericInlineModelAdminmediumCVSS 4EPSS 0.6%
- CVE-2026-3902: Django ASGI header spoofing via underscore/hyphen conflationhighCVSS 7.5EPSS 0.5%
- CVE-2026-33034: Django memory limit bypass in ASGI requestshighCVSS 7.5EPSS 0.9%
- CVE-2026-33033: Django DoS in MultiPartParser via crafted multipart uploadsmediumCVSS 6.5EPSS 0.9%
- CVE-2026-25673: Django denial of service in URLField via Unicode normalization on WindowshighCVSS 7.5EPSS 1.1%
- CVE-2025-13473: Django user enumeration via timing attack in mod_wsgi handlermediumCVSS 4EPSS 0.8%
- CVE-2026-1285: Django denial of service in Truncator HTML methodsmediumCVSS 4EPSS 1.1%
- CVE-2025-14550: Django DoS via inefficient algorithmic complexity in ASGIRequestmediumCVSS 4EPSS 1.1%
Most severe Django Software Foundation vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-64459: Django SQL injection in QuerySet and Q objects via _connector argumentcriticalCVSS 9.1EPSS 19.4%
- CVE-2025-64458: Django denial of service in HttpResponseRedirect on WindowshighCVSS 7.5EPSS 1.9%
- CVE-2026-25673: Django denial of service in URLField via Unicode normalization on WindowshighCVSS 7.5EPSS 1.1%
- CVE-2026-33034: Django memory limit bypass in ASGI requestshighCVSS 7.5EPSS 0.9%
- CVE-2026-3902: Django ASGI header spoofing via underscore/hyphen conflationhighCVSS 7.5EPSS 0.5%
- CVE-2025-57833: Django SQL injection in FilteredRelation column aliaseshighCVSS 7.1EPSS 16.8%
- CVE-2025-59681: Django SQL injection in column aliases on MySQL and MariaDBhighCVSS 7.1EPSS 0.6%
- CVE-2026-1207: Django SQL injection in RasterField lookups on PostGIShighCVSS 5.4EPSS 13.3%
- CVE-2026-1287: Django SQL injection in FilteredRelation column aliaseshighCVSS 5.4EPSS 0.8%
- CVE-2026-33033: Django DoS in MultiPartParser via crafted multipart uploadsmediumCVSS 6.5EPSS 0.9%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 3 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 1 | 0 | |
| 10 Aug 2026 | 1 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 1 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/django-software-foundation.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Django Software Foundation vulnerabilities", https://junglewise.ai/threats/vendors/django-software-foundation, 28 September 2026.