Dependency scanning
Check whether django is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-53877
Django: GDALRaster may over-read heap memory when constructed from bytes
CVE-2026-53878
Django: DomainNameValidator permits newline characters that may enable HTTP header injection
CVE-2026-48588
Django: cache middleware may expose private responses when unrelated request cookies are present
CVE-2026-7666
Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
CVE-2026-5766
Django has an Improper Handling of Length Parameter Inconsistency
CVE-2026-4277
Django vulnerable to privilege abuse in GenericInlineModelAdmin
CVE-2026-33034
Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit
CVE-2025-14550
Django has Inefficient Algorithmic Complexity
CVE-2025-13372
Django is vulnerable to SQL injection in column aliases
CVE-2025-64458
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2025-32873
Django has a denial-of-service possibility in strip_tags()
CVE-2024-53907
Django denial-of-service in django.utils.html.strip_tags()
CVE-2026-6873
Django: signed cookies are vulnerable to salt namespace collisions
CVE-2026-48587
Django: has_vary_header may expose cached responses when Vary values contain whitespace
CVE-2026-8404
Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
CVE-2026-35192
Django Uses Persistent Cookies Containing Sensitive Information
CVE-2026-6907
Django Uses Cache Containing Sensitive Information
CVE-2026-4292
Django vulnerable to privilege abuse in ModelAdmin.list_editable
CVE-2026-3902
Django vulnerable to ASGI header spoofing via underscore/hyphen conflation
CVE-2026-33033
Django has potential DoS via MultiPartParser through crafted multipart uploads
CVE-2026-25674
Django has a Race Condition vulnerability
CVE-2026-25673
Django vulnerable to Uncontrolled Resource Consumption
CVE-2026-1207
Django has an SQL Injection issue
CVE-2026-1287
Django has an SQL Injection issue
CVE-2026-1312
Django has an SQL Injection issue
CVE-2026-1285
Django has Inefficient Algorithmic Complexity
CVE-2025-13473
Django has Observable Timing Discrepancy
CVE-2025-64460
Django is vulnerable to DoS via XML serializer text extraction
CVE-2025-59682
Django vulnerable to partial directory traversal via archives
CVE-2025-59681
Django vulnerable to SQL injection in column aliases
CVE-2025-57833
Django is subject to SQL injection through its column aliases
CVE-2025-48432
Django Improper Output Neutralization for Logs vulnerability
CVE-2024-56374
Django has a potential denial-of-service vulnerability in IPv6 validation
CVE-2024-53908
Django SQL injection in HasKey(lhs, rhs) on Oracle
CVE-2024-39329
Django vulnerable to user enumeration attack
CVE-2024-38875
Django vulnerable to Denial of Service
CVE-2024-39614
Django vulnerable to Denial of Service
CVE-2024-39330
Django Path Traversal vulnerability
CVE-2024-27351
Regular expression denial-of-service in Django
CVE-2024-24680
Django denial-of-service attack in the intcomma template filter
CVE-2025-26699
Django vulnerable to Allocation of Resources Without Limits or Throttling
CVE-2026-15830
CVE-2026-15830
CVE-2026-8404
CVE-2026-8404
CVE-2026-6873
CVE-2026-6873
CVE-2026-35193
CVE-2026-35193
CVE-2026-48587
CVE-2026-48587
CVE-2026-53878
CVE-2026-53878
CVE-2026-48588
CVE-2026-48588
CVE-2026-53877
CVE-2026-53877
CVE-2026-35193
Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary
CVE-2026-7666
CVE-2026-7666
CVE-2026-25673
Django vulnerable to Uncontrolled Resource Consumption
CVE-2026-25674
Django has a Race Condition vulnerability
CVE-2020-9402
CVE-2020-9402
CVE-2020-9402
SQL injection in Django
CVE-2020-9402
CVE-2020-9402
CVE-2019-11358
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2024-45231
Django allows enumeration of user e-mail addresses
CVE-2024-45231
Django allows enumeration of user e-mail addresses
CVE-2025-59682
Django vulnerable to partial directory traversal via archives
CVE-2013-1665
XML External Entity (XXE) in Django
CVE-2013-1664
XML Entity Expansion (XEE) in Django
CVE-2013-1665
XML External Entity (XXE) in Django
CVE-2013-1664
XML Entity Expansion (XEE) in Django
CVE-2007-0404
Django Arbitrary Code Execution
CVE-2007-0405
Django Improper Access Control
CVE-2019-11358
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2007-0405
Django Improper Access Control
CVE-2007-0404
Django Arbitrary Code Execution
CVE-2011-0697
CVE-2011-0697
CVE-2011-0697
Cross-site scripting in django
CVE-2010-4535
CVE-2010-4535
CVE-2010-4535
Improper date handling in Django
CVE-2010-4534
CVE-2010-4534
CVE-2010-4534
Improper query string handling in Django
CVE-2011-0696
CVE-2011-0696
CVE-2011-0696
Cross-site request forgery in Django
CVE-2011-0696
CVE-2011-0696
CVE-2010-4534
CVE-2010-4534
CVE-2010-4535
CVE-2010-4535
CVE-2011-0697
CVE-2011-0697
CVE-2026-6907
CVE-2026-6907
CVE-2026-5766
CVE-2026-5766
CVE-2026-4292
CVE-2026-4292
CVE-2026-4277
CVE-2026-4277
CVE-2025-57833
CVE-2025-57833
CVE-2025-59681
CVE-2025-59681
CVE-2025-13372
CVE-2025-13372
CVE-2026-3902
CVE-2026-3902
CVE-2026-35192
CVE-2026-35192
CVE-2026-33034
CVE-2026-33034
CVE-2026-1312
CVE-2026-1312
CVE-2026-33033
CVE-2026-33033
CVE-2026-1287
CVE-2026-1287
CVE-2026-1207
CVE-2026-1207
CVE-2026-1285
CVE-2026-1285
CVE-2025-14550
CVE-2025-14550
CVE-2025-48432
CVE-2025-48432
CVE-2025-13473
CVE-2025-13473
CVE-2025-32873
CVE-2025-32873
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes