100 Total advisories
100 Vulnerabilities
0 Malware

Dependency scanning

Check whether django is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 4.8
PyPI

CVE-2026-53877

Django: GDALRaster may over-read heap memory when constructed from bytes

MEDIUM 6.1
PyPI

CVE-2026-53878

Django: DomainNameValidator permits newline characters that may enable HTTP header injection

LOW 3.1
PyPI

CVE-2026-48588

Django: cache middleware may expose private responses when unrelated request cookies are present

LOW 3.1
PyPI

CVE-2026-7666

Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake

MEDIUM 5.3
PyPI

CVE-2026-5766

Django has an Improper Handling of Length Parameter Inconsistency

UNKNOWN
PyPI

CVE-2026-4277

Django vulnerable to privilege abuse in GenericInlineModelAdmin

HIGH 7.5
PyPI

CVE-2026-33034

Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit

UNKNOWN
PyPI

CVE-2025-14550

Django has Inefficient Algorithmic Complexity

MEDIUM 4.3
PyPI

CVE-2025-13372

Django is vulnerable to SQL injection in column aliases

HIGH 7.5
PyPI

CVE-2025-64458

Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

MEDIUM 5.3
PyPI

CVE-2025-32873

Django has a denial-of-service possibility in strip_tags()

HIGH 7.5
PyPI

CVE-2024-53907

Django denial-of-service in django.utils.html.strip_tags()

LOW 3.1
PyPI

CVE-2026-6873

Django: signed cookies are vulnerable to salt namespace collisions

LOW 3.1
PyPI

CVE-2026-48587

Django: has_vary_header may expose cached responses when Vary values contain whitespace

LOW 3.1
PyPI

CVE-2026-8404

Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling

UNKNOWN
PyPI

CVE-2026-35192

Django Uses Persistent Cookies Containing Sensitive Information

MEDIUM 4.3
PyPI

CVE-2026-6907

Django Uses Cache Containing Sensitive Information

LOW 2.7
PyPI

CVE-2026-4292

Django vulnerable to privilege abuse in ModelAdmin.list_editable

HIGH 7.5
PyPI

CVE-2026-3902

Django vulnerable to ASGI header spoofing via underscore/hyphen conflation

MEDIUM 6.5
PyPI

CVE-2026-33033

Django has potential DoS via MultiPartParser through crafted multipart uploads

LOW 3.7
PyPI

CVE-2026-25674

Django has a Race Condition vulnerability

HIGH 7.5
PyPI

CVE-2026-25673

Django vulnerable to Uncontrolled Resource Consumption

UNKNOWN
PyPI

CVE-2026-1207

Django has an SQL Injection issue

UNKNOWN
PyPI

CVE-2026-1287

Django has an SQL Injection issue

MEDIUM 5.4
PyPI

CVE-2026-1312

Django has an SQL Injection issue

UNKNOWN
PyPI

CVE-2026-1285

Django has Inefficient Algorithmic Complexity

UNKNOWN
PyPI

CVE-2025-13473

Django has Observable Timing Discrepancy

UNKNOWN
PyPI

CVE-2025-64460

Django is vulnerable to DoS via XML serializer text extraction

LOW 3.1
PyPI

CVE-2025-59682

Django vulnerable to partial directory traversal via archives

HIGH 7.1
PyPI

CVE-2025-59681

Django vulnerable to SQL injection in column aliases

HIGH 7.1
PyPI

CVE-2025-57833

Django is subject to SQL injection through its column aliases

MEDIUM 4.0
PyPI

CVE-2025-48432

Django Improper Output Neutralization for Logs vulnerability

MEDIUM 5.8
PyPI

CVE-2024-56374

Django has a potential denial-of-service vulnerability in IPv6 validation

CRITICAL 9.8
PyPI

CVE-2024-53908

Django SQL injection in HasKey(lhs, rhs) on Oracle

MEDIUM 5.3
PyPI

CVE-2024-39329

Django vulnerable to user enumeration attack

HIGH 7.5
PyPI

CVE-2024-38875

Django vulnerable to Denial of Service

HIGH 7.5
PyPI

CVE-2024-39614

Django vulnerable to Denial of Service

HIGH 7.5
PyPI

CVE-2024-39330

Django Path Traversal vulnerability

MEDIUM 5.3
PyPI

CVE-2024-27351

Regular expression denial-of-service in Django

MEDIUM 5.9
PyPI

CVE-2024-24680

Django denial-of-service attack in the intcomma template filter

MEDIUM 5.0
PyPI

CVE-2025-26699

Django vulnerable to Allocation of Resources Without Limits or Throttling

UNKNOWN
PyPI

CVE-2026-15830

CVE-2026-15830

MEDIUM 5.3
PyPI

CVE-2026-8404

CVE-2026-8404

MEDIUM 4.3
PyPI

CVE-2026-6873

CVE-2026-6873

UNKNOWN
PyPI

CVE-2026-35193

CVE-2026-35193

MEDIUM 5.3
PyPI

CVE-2026-48587

CVE-2026-48587

UNKNOWN
PyPI

CVE-2026-53878

CVE-2026-53878

MEDIUM 5.3
PyPI

CVE-2026-48588

CVE-2026-48588

UNKNOWN
PyPI

CVE-2026-53877

CVE-2026-53877

LOW 3.1
PyPI

CVE-2026-35193

Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary

UNKNOWN
PyPI

CVE-2026-7666

CVE-2026-7666

HIGH 7.5
PyPI

CVE-2026-25673

Django vulnerable to Uncontrolled Resource Consumption

LOW 3.7
PyPI

CVE-2026-25674

Django has a Race Condition vulnerability

UNKNOWN
PyPI

CVE-2020-9402

CVE-2020-9402

HIGH 8.8
PyPI

CVE-2020-9402

SQL injection in Django

HIGH 8.8
PyPI

CVE-2020-9402

CVE-2020-9402

MEDIUM 6.1
npm

CVE-2019-11358

XSS in jQuery as used in Drupal, Backdrop CMS, and other products

LOW 3.7
PyPI

CVE-2024-45231

Django allows enumeration of user e-mail addresses

LOW 3.7
PyPI

CVE-2024-45231

Django allows enumeration of user e-mail addresses

LOW 3.1
PyPI

CVE-2025-59682

Django vulnerable to partial directory traversal via archives

UNKNOWN
PyPI

CVE-2013-1665

XML External Entity (XXE) in Django

UNKNOWN
PyPI

CVE-2013-1664

XML Entity Expansion (XEE) in Django

UNKNOWN
PyPI

CVE-2013-1665

XML External Entity (XXE) in Django

UNKNOWN
PyPI

CVE-2013-1664

XML Entity Expansion (XEE) in Django

UNKNOWN
PyPI

CVE-2007-0404

Django Arbitrary Code Execution

UNKNOWN
PyPI

CVE-2007-0405

Django Improper Access Control

MEDIUM 6.1
PyPI

CVE-2019-11358

XSS in jQuery as used in Drupal, Backdrop CMS, and other products

UNKNOWN
PyPI

CVE-2007-0405

Django Improper Access Control

UNKNOWN
PyPI

CVE-2007-0404

Django Arbitrary Code Execution

UNKNOWN
PyPI

CVE-2011-0697

CVE-2011-0697

MEDIUM 6.1
PyPI

CVE-2011-0697

Cross-site scripting in django

UNKNOWN
PyPI

CVE-2010-4535

CVE-2010-4535

HIGH 7.5
PyPI

CVE-2010-4535

Improper date handling in Django

UNKNOWN
PyPI

CVE-2010-4534

CVE-2010-4534

MEDIUM 6.5
PyPI

CVE-2010-4534

Improper query string handling in Django

UNKNOWN
PyPI

CVE-2011-0696

CVE-2011-0696

HIGH 7.5
PyPI

CVE-2011-0696

Cross-site request forgery in Django

UNKNOWN
PyPI

CVE-2011-0696

CVE-2011-0696

UNKNOWN
PyPI

CVE-2010-4534

CVE-2010-4534

UNKNOWN
PyPI

CVE-2010-4535

CVE-2010-4535

UNKNOWN
PyPI

CVE-2011-0697

CVE-2011-0697

MEDIUM 5.3
PyPI

CVE-2026-6907

CVE-2026-6907

UNKNOWN
PyPI

CVE-2026-5766

CVE-2026-5766

LOW 2.7
PyPI

CVE-2026-4292

CVE-2026-4292

CRITICAL 9.8
PyPI

CVE-2026-4277

CVE-2026-4277

HIGH 8.1
PyPI

CVE-2025-57833

CVE-2025-57833

CRITICAL 9.8
PyPI

CVE-2025-59681

CVE-2025-59681

MEDIUM 4.3
PyPI

CVE-2025-13372

CVE-2025-13372

HIGH 7.5
PyPI

CVE-2026-3902

CVE-2026-3902

MEDIUM 6.5
PyPI

CVE-2026-35192

CVE-2026-35192

HIGH 7.5
PyPI

CVE-2026-33034

CVE-2026-33034

MEDIUM 5.4
PyPI

CVE-2026-1312

CVE-2026-1312

MEDIUM 6.5
PyPI

CVE-2026-33033

CVE-2026-33033

MEDIUM 5.4
PyPI

CVE-2026-1287

CVE-2026-1287

MEDIUM 5.4
PyPI

CVE-2026-1207

CVE-2026-1207

HIGH 7.5
PyPI

CVE-2026-1285

CVE-2026-1285

HIGH 7.5
PyPI

CVE-2025-14550

CVE-2025-14550

UNKNOWN
PyPI

CVE-2025-48432

CVE-2025-48432

MEDIUM 5.3
PyPI

CVE-2025-13473

CVE-2025-13473

UNKNOWN
PyPI

CVE-2025-32873

CVE-2025-32873

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes