<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:20:01.269275+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03582</id>
    <title>bdu:2023-03582</title>
    <updated>2026-10-03T08:20:01.458976+00:00</updated>
    <content>bdu:2023-03582</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03582"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-django-2023-31047</id>
    <title>BIT-django-2023-31047</title>
    <updated>2026-10-03T08:20:01.459066+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: django</p>
<p>In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-django-2023-31047"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-212546</id>
    <title>EUVD-2026-212546</title>
    <updated>2026-10-03T08:20:01.459138+00:00</updated>
    <content>EUVD-2026-212546</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-212546"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-31047</id>
    <title>fkie_cve-2023-31047</title>
    <updated>2026-10-03T08:20:01.459167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-31047"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r3xc-prgr-mg9p</id>
    <title>GHSA-r3xc-prgr-mg9p — Django bypasses validation when using one form field to upload multiple files</title>
    <updated>2026-10-03T08:20:01.459388+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Django</p>
<p>In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r3xc-prgr-mg9p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-31047</id>
    <title>gsd-2023-31047</title>
    <updated>2026-10-03T08:20:01.459457+00:00</updated>
    <content>gsd-2023-31047</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-31047"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1286</id>
    <title>OESA-2023-1286 — python-django security update</title>
    <updated>2026-10-03T08:20:01.459486+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: python-django, openEuler:20.03-LTS-SP3: python-django, openEuler:22.03-LTS: python-django, openEuler:22.03-LTS-SP1: python-django</p>
<p>A high-level Python Web framework that encourages rapid development and clean, pragmatic design.

Security Fix(es):

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django&amp;apos;s &amp;quot;Uploading multiple files&amp;quot; documentation suggested otherwise.(CVE-2023-31047)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1286"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12943-1</id>
    <title>openSUSE-SU-2024:12943-1 — python310-Django-4.2.1-1.1 on GA media</title>
    <updated>2026-10-03T08:20:01.459551+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-Django-4.2.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12943-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2023-61</id>
    <title>PYSEC-2023-61</title>
    <updated>2026-10-03T08:20:01.459586+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: django</p>
<p>In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2023-61"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:4591</id>
    <title>RHSA-2023:4591 — Red Hat Security Advisory: RHUI 4.5.0 release - Security, Bug Fixes, and Enhancements</title>
    <updated>2026-10-03T08:20:01.459633+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sqlparse: Parser contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service) python-django: Potential bypass of validation when uploading multiple files using one form field</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:4591"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:2839-1</id>
    <title>SUSE-SU-2023:2839-1 — Security update for python-Django</title>
    <updated>2026-10-03T08:20:01.459676+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-Django</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:2839-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-31047</id>
    <title>UBUNTU-CVE-2023-31047</title>
    <updated>2026-10-03T08:20:01.459713+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python-django, Ubuntu:Pro:16.04:LTS: python-django, Ubuntu:18.04:LTS: python-django, Ubuntu:20.04:LTS: python-django, Ubuntu:22.04:LTS: python-django</p>
<p>In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-31047"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1137</id>
    <title>WID-SEC-W-2023-1137 — Django: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T08:20:01.459777+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Django ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1137"/>
  </entry>
</feed>
