logo

Django Releases Security Patches to Address DoS and Permission Vulnerabilities

ID: e6ef8809-c270-5505-a7ac-9ab09b080d56

STIX ID: report--e6ef8809-c270-5505-a7ac-9ab09b080d56

Feed Name: securityonline.info

Threat Score
45/100

Date Published: 2026-03-04

Date Updated: 2026-04-23

Author: Ddos

...
...

Django published security updates for supported branches to address two vulnerabilities: CVE-2026-25673, a moderate DoS risk in URLField on Windows due to costly Unicode normalization, and CVE-2026-25674, a low-severity file-permission issue from reliance on process umask; fixes are applied to main and released branches (6.0.3, 5.2.12, 4.2.29), and developers are urged to upgrade and review affected code such as custom validators and file-storage logic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.