<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:10:14 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-06450</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-06450</link>
      <description>bdu:2025-06450</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-06450</guid>
    </item>
    <item>
      <title>BIT-django-2025-48432</title>
      <link>https://cve.radiocsirt.org/vuln/bit-django-2025-48432</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: django&lt;/p&gt;
&lt;p&gt;An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: django&lt;/p&gt;
&lt;p&gt;An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-django-2025-48432</guid>
    </item>
    <item>
      <title>EUVD-2026-243996</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-243996</link>
      <description>EUVD-2026-243996</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-243996</guid>
    </item>
    <item>
      <title>fkie_cve-2025-48432</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-48432</link>
      <description>&lt;p&gt;An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-48432</guid>
    </item>
    <item>
      <title>GHSA-7xr5-9hcq-chf9 — Django Improper Output Neutralization for Logs vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7xr5-9hcq-chf9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Django&lt;/p&gt;
&lt;p&gt;An issue was discovered in Django 5.2 before 5.2.2, 5.1 before 5.1.10, and 4.2 before 4.2.22. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Django&lt;/p&gt;
&lt;p&gt;An issue was discovered in Django 5.2 before 5.2.2, 5.1 before 5.1.10, and 4.2 before 4.2.22. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7xr5-9hcq-chf9</guid>
    </item>
    <item>
      <title>OESA-2025-1617 — python-django security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1617</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: python-django&lt;/p&gt;
&lt;p&gt;A high-level Python Web framework that encourages rapid development and clean, pragmatic design.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability, which was classified as problematic, was found in Django up to 4.2.21/5.1.9/5.2.1 (Content Management System).CWE is classifying the issue as CWE-117. The product does not neutralize or incorrectly neutralizes output that is written to logs.This is going to have an impact on integrity.Upgrading to version 4.2.22, 5.1.10 or 5.2.2 eliminates this vulnerability.(CVE-2025-48432)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: python-django&lt;/p&gt;
&lt;p&gt;A high-level Python Web framework that encourages rapid development and clean, pragmatic design.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability, which was classified as problematic, was found in Django up to 4.2.21/5.1.9/5.2.1 (Content Management System).CWE is classifying the issue as CWE-117. The product does not neutralize or incorrectly neutralizes output that is written to logs.This is going to have an impact on integrity.Upgrading to version 4.2.22, 5.1.10 or 5.2.2 eliminates this vulnerability.(CVE-2025-48432)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1617</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15267-1 — python311-Django-5.2.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15267-1</link>
      <description>&lt;p&gt;python311-Django-5.2.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-Django-5.2.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15267-1</guid>
    </item>
    <item>
      <title>PYSEC-2025-47</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2025-47</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django&lt;/p&gt;
&lt;p&gt;An issue was discovered in Django 5.2 before 5.2.2, 5.1 before 5.1.10, and 4.2 before 4.2.22. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django&lt;/p&gt;
&lt;p&gt;An issue was discovered in Django 5.2 before 5.2.2, 5.1 before 5.1.10, and 4.2 before 4.2.22. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2025-47</guid>
    </item>
    <item>
      <title>RHSA-2025:14686 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:14686</link>
      <description>&lt;p&gt;setuptools: Path Traversal Vulnerability in setuptools PackageIndex django: Django Path Injection Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;setuptools: Path Traversal Vulnerability in setuptools PackageIndex django: Django Path Injection Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:14686</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01952-1 — Security update for python-Django</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01952-1</link>
      <description>&lt;p&gt;Security update for python-Django&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Django&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01952-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-48432</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48432</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-django, Ubuntu:Pro:16.04:LTS: python-django, Ubuntu:Pro:18.04:LTS: python-django, Ubuntu:Pro:20.04:LTS: python-django, Ubuntu:22.04:LTS: python-django, Ubuntu:24.04:LTS: python-django, Ubuntu:25.10: python-django&lt;/p&gt;
&lt;p&gt;An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-django, Ubuntu:Pro:16.04:LTS: python-django, Ubuntu:Pro:18.04:LTS: python-django, Ubuntu:Pro:20.04:LTS: python-django, Ubuntu:22.04:LTS: python-django, Ubuntu:24.04:LTS: python-django, Ubuntu:25.10: python-django&lt;/p&gt;
&lt;p&gt;An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48432</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1245 — Django: Schwachstelle ermöglicht Manipulation von Dateien</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1245</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Django ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Django ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1245</guid>
    </item>
  </channel>
</rss>
