<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:44:49 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-55500</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-55500</link>
      <description>EUVD-2026-55500</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-55500</guid>
    </item>
    <item>
      <title>fkie_cve-2019-13177</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-13177</link>
      <description>&lt;p&gt;verification.py in django-rest-registration (aka Django REST Registration library) before 0.5.0 relies on a static string for signatures (i.e., the Django Signing API is misused), which allows remote attackers to spoof the verification process. This occurs because incorrect code refactoring led to calling a security-critical function with an incorrect argument.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;verification.py in django-rest-registration (aka Django REST Registration library) before 0.5.0 relies on a static string for signatures (i.e., the Django Signing API is misused), which allows remote attackers to spoof the verification process. This occurs because incorrect code refactoring led to calling a security-critical function with an incorrect argument.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-13177</guid>
    </item>
    <item>
      <title>GHSA-p3w6-jcg4-52xh — Improper Verification of Cryptographic Signature in django-rest-registration</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p3w6-jcg4-52xh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django-rest-registration&lt;/p&gt;
&lt;p&gt;## Misusing the Django Signer API leads to predictable signatures used in verification emails&lt;/p&gt;
&lt;p&gt;### Impact
The vulnerability is a high severity one. Anyone using Django REST Registration library versions `0.2.*` - `0.4.*` with e-mail verification option (which is recommended, but needs [additional configuration](https://django-rest-registration.readthedocs.io/en/latest/quickstart.html#preferred-configuration)) is affected.
In the worst case, the attacker can take over any Django user by resetting his/her password without even receiving the reset password verification link, just by guessing the signature from publicly available data (more detailed description below).&lt;/p&gt;
&lt;p&gt;### Patches
The problem has been patched in version `0.5.0`. All library users should upgrade to version `0.5.0` or higher.
The fix will invalidate all previously generated signatures , and in consequence, all verification links in previously sent verification e-mails. Therefore semi-major version `0.5.0` was released instead of version `0.4.6` to mark that incompatibility.&lt;/p&gt;
&lt;p&gt;### Workarounds
The easiest way way is to disable the verification options by using something like the minimal configuration described [here](https://django-rest-registration.readthedocs.io/en/latest/quickstart.html#minimal-configuration). This will unfortunately disable checking whether the given e-mail is valid and make unable to users who registered an account but didn&amp;#39;t verify it before config change.&lt;/p&gt;
&lt;p&gt;Less harsh way is to temporarily dis…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django-rest-registration&lt;/p&gt;
&lt;p&gt;## Misusing the Django Signer API leads to predictable signatures used in verification emails&lt;/p&gt;
&lt;p&gt;### Impact
The vulnerability is a high severity one. Anyone using Django REST Registration library versions `0.2.*` - `0.4.*` with e-mail verification option (which is recommended, but needs [additional configuration](https://django-rest-registration.readthedocs.io/en/latest/quickstart.html#preferred-configuration)) is affected.
In the worst case, the attacker can take over any Django user by resetting his/her password without even receiving the reset password verification link, just by guessing the signature from publicly available data (more detailed description below).&lt;/p&gt;
&lt;p&gt;### Patches
The problem has been patched in version `0.5.0`. All library users should upgrade to version `0.5.0` or higher.
The fix will invalidate all previously generated signatures , and in consequence, all verification links in previously sent verification e-mails. Therefore semi-major version `0.5.0` was released instead of version `0.4.6` to mark that incompatibility.&lt;/p&gt;
&lt;p&gt;### Workarounds
The easiest way way is to disable the verification options by using something like the minimal configuration described [here](https://django-rest-registration.readthedocs.io/en/latest/quickstart.html#minimal-configuration). This will unfortunately disable checking whether the given e-mail is valid and make unable to users who registered an account but didn&amp;#39;t verify it before config change.&lt;/p&gt;
&lt;p&gt;Less harsh way is to temporarily dis…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p3w6-jcg4-52xh</guid>
    </item>
    <item>
      <title>gsd-2019-13177</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-13177</link>
      <description>gsd-2019-13177</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-13177</guid>
    </item>
    <item>
      <title>PYSEC-2019-20</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2019-20</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django-rest-registration&lt;/p&gt;
&lt;p&gt;verification.py in django-rest-registration (aka Django REST Registration library) before 0.5.0 relies on a static string for signatures (i.e., the Django Signing API is misused), which allows remote attackers to spoof the verification process. This occurs because incorrect code refactoring led to calling a security-critical function with an incorrect argument.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django-rest-registration&lt;/p&gt;
&lt;p&gt;verification.py in django-rest-registration (aka Django REST Registration library) before 0.5.0 relies on a static string for signatures (i.e., the Django Signing API is misused), which allows remote attackers to spoof the verification process. This occurs because incorrect code refactoring led to calling a security-critical function with an incorrect argument.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2019-20</guid>
    </item>
  </channel>
</rss>
