Official source evidencegroups.google.comVersioned article
Official source article · groups.google.com

django-announce - Google Groups

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publishergroups.google.com
Article IDNo stable ID in source URL
Verified snapshot27 Sept 2026, 02:00 UTC
Linked CVEs32

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-1207Potential SQL injection via raster lookups on PostGIS
  • CVE-2026-1287Potential SQL injection in column aliases via control characters
  • CVE-2026-1312Potential SQL injection via QuerySet.order_by and FilteredRelation
  • CVE-2026-25673Potential denial-of-service vulnerability in URLField via Unicode normalization on Windows
  • CVE-2026-48588Potential exposure of private data via cached Set-Cookie response
  • CVE-2026-53877Heap buffer over-read in GDALRaster
  • CVE-2026-53878Header injection possibility since DomainNameValidator accepted newlines in input
  • CVE-2026-4277Privilege abuse in GenericInlineModelAdmin
  • CVE-2026-48587Potential exposure of private data via whitespace padding in Vary header
  • CVE-2026-35193Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddleware
  • CVE-2026-8404Potential exposure of private data via case-sensitive Cache-Control directives in UpdateCacheMiddleware
  • CVE-2026-6873Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie
  • CVE-2026-7666Potential unencrypted email transmission via STARTTLS in the SMTP backend
  • CVE-2026-33034Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass
  • CVE-2026-3902ASGI header spoofing via underscore/hyphen conflation
  • CVE-2026-33033Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload
  • CVE-2026-4292Privilege abuse in ModelAdmin.list_editable
  • CVE-2026-25674Potential incorrect permissions on newly created file system objects
  • CVE-2025-14550Potential denial-of-service vulnerability via repeated headers when using ASGI
  • CVE-2026-1285Potential denial-of-service vulnerability in django.utils.text.Truncator HTML methods
  • CVE-2025-13473Username enumeration through timing difference in mod_wsgi authentication handler
  • CVE-2025-64460Potential denial-of-service vulnerability in XML serializer text extraction
  • CVE-2025-13372Potential SQL injection in FilteredRelation column aliases on PostgreSQL
  • CVE-2025-59682djangoproject Django — Relative Path Traversal
  • CVE-2025-59681djangoproject Django — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
  • CVE-2025-57833djangoproject Django — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
  • CVE-2025-48432Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs
  • CVE-2025-27556djangoproject Django — Allocation of Resources Without Limits or Throttling
  • CVE-2025-26699The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings
  • CVE-2024-56374Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack
  • CVE-2024-53907The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities
  • CVE-2024-53908Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value

Source and provenance

Original title: django-announce - Google Groups. Captured 27 Sept 2026, 02:00 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗