<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:20:10 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-03582</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03582</link>
      <description>bdu:2023-03582</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03582</guid>
    </item>
    <item>
      <title>BIT-django-2023-31047</title>
      <link>https://cve.radiocsirt.org/vuln/bit-django-2023-31047</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: django&lt;/p&gt;
&lt;p&gt;In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django&amp;#39;s &amp;#34;Uploading multiple files&amp;#34; documentation suggested otherwise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: django&lt;/p&gt;
&lt;p&gt;In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django&amp;#39;s &amp;#34;Uploading multiple files&amp;#34; documentation suggested otherwise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-django-2023-31047</guid>
    </item>
    <item>
      <title>EUVD-2026-212546</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-212546</link>
      <description>EUVD-2026-212546</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-212546</guid>
    </item>
    <item>
      <title>fkie_cve-2023-31047</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-31047</link>
      <description>&lt;p&gt;In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django&amp;#39;s &amp;#34;Uploading multiple files&amp;#34; documentation suggested otherwise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django&amp;#39;s &amp;#34;Uploading multiple files&amp;#34; documentation suggested otherwise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-31047</guid>
    </item>
    <item>
      <title>GHSA-r3xc-prgr-mg9p — Django bypasses validation when using one form field to upload multiple files</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r3xc-prgr-mg9p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Django&lt;/p&gt;
&lt;p&gt;In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django&amp;#39;s &amp;#34;Uploading multiple files&amp;#34; documentation suggested otherwise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Django&lt;/p&gt;
&lt;p&gt;In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django&amp;#39;s &amp;#34;Uploading multiple files&amp;#34; documentation suggested otherwise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r3xc-prgr-mg9p</guid>
    </item>
    <item>
      <title>gsd-2023-31047</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-31047</link>
      <description>gsd-2023-31047</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-31047</guid>
    </item>
    <item>
      <title>OESA-2023-1286 — python-django security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1286</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: python-django, openEuler:20.03-LTS-SP3: python-django, openEuler:22.03-LTS: python-django, openEuler:22.03-LTS-SP1: python-django&lt;/p&gt;
&lt;p&gt;A high-level Python Web framework that encourages rapid development and clean, pragmatic design.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django&amp;amp;apos;s &amp;amp;quot;Uploading multiple files&amp;amp;quot; documentation suggested otherwise.(CVE-2023-31047)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: python-django, openEuler:20.03-LTS-SP3: python-django, openEuler:22.03-LTS: python-django, openEuler:22.03-LTS-SP1: python-django&lt;/p&gt;
&lt;p&gt;A high-level Python Web framework that encourages rapid development and clean, pragmatic design.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django&amp;amp;apos;s &amp;amp;quot;Uploading multiple files&amp;amp;quot; documentation suggested otherwise.(CVE-2023-31047)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1286</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12943-1 — python310-Django-4.2.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12943-1</link>
      <description>&lt;p&gt;python310-Django-4.2.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python310-Django-4.2.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12943-1</guid>
    </item>
    <item>
      <title>PYSEC-2023-61</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2023-61</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django&lt;/p&gt;
&lt;p&gt;In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django&amp;#39;s &amp;#34;Uploading multiple files&amp;#34; documentation suggested otherwise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django&lt;/p&gt;
&lt;p&gt;In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django&amp;#39;s &amp;#34;Uploading multiple files&amp;#34; documentation suggested otherwise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2023-61</guid>
    </item>
    <item>
      <title>RHSA-2023:4591 — Red Hat Security Advisory: RHUI 4.5.0 release - Security, Bug Fixes, and Enhancements</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:4591</link>
      <description>&lt;p&gt;sqlparse: Parser contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service) python-django: Potential bypass of validation when uploading multiple files using one form field&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;sqlparse: Parser contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service) python-django: Potential bypass of validation when uploading multiple files using one form field&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:4591</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:2839-1 — Security update for python-Django</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:2839-1</link>
      <description>&lt;p&gt;Security update for python-Django&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Django&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:2839-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-31047</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-31047</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-django, Ubuntu:Pro:16.04:LTS: python-django, Ubuntu:18.04:LTS: python-django, Ubuntu:20.04:LTS: python-django, Ubuntu:22.04:LTS: python-django&lt;/p&gt;
&lt;p&gt;In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django&amp;#39;s &amp;#34;Uploading multiple files&amp;#34; documentation suggested otherwise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-django, Ubuntu:Pro:16.04:LTS: python-django, Ubuntu:18.04:LTS: python-django, Ubuntu:20.04:LTS: python-django, Ubuntu:22.04:LTS: python-django&lt;/p&gt;
&lt;p&gt;In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django&amp;#39;s &amp;#34;Uploading multiple files&amp;#34; documentation suggested otherwise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-31047</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1137 — Django: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1137</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Django ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Django ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1137</guid>
    </item>
  </channel>
</rss>
