Skip to content
Threat Feed

Tag

Django

5 briefs RSS
high advisory

Remote Code Execution via eval() in django-haystack Elasticsearch Deserialization

A critical remote code execution (RCE) vulnerability in the Elasticsearch backend of django-haystack allows attackers to execute arbitrary Python commands by manipulating `SearchField` aliases and indexed content, leading to full compromise of the Django application.

django-haystack rce python django elasticsearch deserialization supply-chain
1r 2t 2i
medium advisory

Django Vulnerability Enables Denial of Service

A remote, unauthenticated attacker can exploit an unspecified vulnerability in Django to conduct a Denial of Service attack, which could disrupt the availability of services running on the affected Django application.

Django denial-of-service web-application
1t
critical threat

Active Exploitation of CVE-2026-1207 in Django Framework

A critical vulnerability, CVE-2026-1207, affecting Django versions prior to 4.2.28, 5.2.11, and 6.0.2, is actively being exploited, posing a significant risk of web server compromise and data exfiltration to organizations using the affected framework.

exploited Django 4.2 +2 web-application vulnerability active-exploitation python django
1c
critical advisory

django-s3file Vulnerable to Relative Path Traversal

The django-s3file package is vulnerable to relative path traversal attacks via the S3FileMiddleware component, allowing attackers to bypass pre-signed upload locations and potentially leading to unauthorized file access and modification.

django-s3file path-traversal web-application django
2r 1t
high advisory

Django Multiple Vulnerabilities Leading to SQL Injection, Information Disclosure, and DoS

A remote, authenticated attacker can exploit multiple vulnerabilities in Django to perform SQL injections, disclose confidential information, or cause a denial-of-service condition.

django sql-injection information-disclosure denial-of-service web-application webserver
2r 2t