<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:47:59.398703+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09775</id>
    <title>bdu:2026-09775</title>
    <updated>2026-10-03T20:47:59.718141+00:00</updated>
    <content>bdu:2026-09775</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09775"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-django-2026-5766</id>
    <title>BIT-django-2026-5766 — Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass</title>
    <updated>2026-10-03T20:47:59.718193+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: django</p>
<p>An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.
ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and causing service degradation.
 
As a reminder, Django expects a limit to be configured at the web server level rather than solely relying on `FILE_UPLOAD_MAX_MEMORY_SIZE`.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Kyle Agronick for reporting this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-django-2026-5766"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-308756</id>
    <title>EUVD-2026-308756</title>
    <updated>2026-10-03T20:47:59.718232+00:00</updated>
    <content>EUVD-2026-308756</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-308756"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-5766</id>
    <title>fkie_cve-2026-5766</title>
    <updated>2026-10-03T20:47:59.718262+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.
ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and causing service degradation.
 
As a reminder, Django expects a limit to be configured at the web server level rather than solely relying on `FILE_UPLOAD_MAX_MEMORY_SIZE`.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Kyle Agronick for reporting this issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-5766"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w26r-rmm8-9c29</id>
    <title>GHSA-w26r-rmm8-9c29 — Django has an Improper Handling of Length Parameter Inconsistency</title>
    <updated>2026-10-03T20:47:59.718288+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Django</p>
<p>An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and causing service degradation.
 
As a reminder, Django expects a limit to be configured at the web server level rather than solely relying on `FILE_UPLOAD_MAX_MEMORY_SIZE`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.</p>
<p>Django thanks Kyle Agronick for reporting this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w26r-rmm8-9c29"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2217</id>
    <title>OESA-2026-2217 — python-django security update</title>
    <updated>2026-10-03T20:47:59.718315+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: python-django</p>
<p>A high-level Python Web framework that encourages rapid development and clean, pragmatic design.

Security Fix(es):</p>
<p>An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.
`MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including excessive whitespace.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Seokchan Yoon for reporting this issue.(CVE-2026-33033)</p>
<p>An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated Content-Length header could bypass the DATA_UPLOAD_MAX_MEMORY_SIZE limit when reading HttpRequest.body, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.(CVE-2026-33034)</p>
<p>This issue was discovered in version 6.0, before 6.0.5, and before 5.2.14. If the session has not been modified, the cookie&amp;amp;#39;s response header does not change, but &amp;amp;quot;SESSION_SAVE_EVERY_REQUEST&amp;amp;quot; is &amp;amp;quot;true&amp;amp;quot;. A remote attacker could steal a user&amp;amp;#39;s session after the user visits a cached public page. Earlier unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) have not b…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2217"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10708-1</id>
    <title>openSUSE-SU-2026:10708-1 — python311-Django4-4.2.30-2.1 on GA media</title>
    <updated>2026-10-03T20:47:59.718364+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-Django4-4.2.30-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10708-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-54</id>
    <title>PYSEC-2026-54</title>
    <updated>2026-10-03T20:47:59.718385+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: django</p>
<p>An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.
ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and causing service degradation.
 
As a reminder, Django expects a limit to be configured at the web server level rather than solely relying on `FILE_UPLOAD_MAX_MEMORY_SIZE`.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Kyle Agronick for reporting this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-54"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:1740-1</id>
    <title>SUSE-SU-2026:1740-1 — Security update for python-Django</title>
    <updated>2026-10-03T20:47:59.718407+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-Django</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:1740-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-5766</id>
    <title>UBUNTU-CVE-2026-5766</title>
    <updated>2026-10-03T20:47:59.718428+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python-django, Ubuntu:Pro:16.04:LTS: python-django, Ubuntu:Pro:18.04:LTS: python-django, Ubuntu:Pro:20.04:LTS: python-django, Ubuntu:22.04:LTS: python-django, Ubuntu:24.04:LTS: python-django, Ubuntu:25.10: python-django, Ubuntu:26.04:LTS: python-django</p>
<p>An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and causing service degradation. As a reminder, Django expects a limit to be configured at the web server level rather than solely relying on `FILE_UPLOAD_MAX_MEMORY_SIZE`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Kyle Agronick for reporting this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-5766"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1373</id>
    <title>WID-SEC-W-2026-1373 — Django: Mehrere Schwachstellen</title>
    <updated>2026-10-03T20:47:59.718461+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Django ausnutzen, um Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1373"/>
  </entry>
</feed>
