PT-2026-56197 · Django+1 · Django+1

·

CVE-2026-53878

·

Published

2026-07-07

·

Updated

2026-08-24

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Django versions prior to 6.0.7 Django versions prior to 5.2.16
Description An issue exists where DomainNameValidator fails to prohibit newlines in domain names. While CharField strips newlines when used via a form field, other implementations may allow them. If an application incorporates these values containing newlines into an HTTP response, header injection can occur. Header injection is a technique used to insert malicious data into HTTP headers, potentially allowing attackers to manipulate the response sent to the client.
Recommendations Update Django to version 6.0.7 or later. Update Django to version 5.2.16 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DJANGO-2026-53878
CVE-2026-53878
ECHO-BC1B-1076-F725
GHSA-8QCX-XF44-272X
OPENSUSE-SU-2026:11236-1
OPENSUSE-SU-2026:11248-1
OPENSUSE-SU-2026:11270-1
OPENSUSE-SU-2026:21313-1
PYSEC-2026-2092

Affected Products

Django
Red Os