django-s3file
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting django-s3filepage 1 of 1
- CVE-2022-24840CRITICALCVSS 9.1EG 9.1✓ Fixed in 5.5.12022-06-09
vulnerable: 0.1.0 ... 5.5.0 (75 versions)
django-s3file is a lightweight file upload input for Django and Amazon S3 . In versions prior to 5.5.1 it was possible to traverse the entire AWS S3 bucket and in most cases to access or delete files. If the `AWS_LOCATION` setting was set,…
- CVE-2026-42196CRITICALCVSS 9.9EG 9.9✓ Fixed in 7.0.22026-05-12
vulnerable: 0.1.0 ... 7.0.1 (84 versions)
django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerable to relative path traversal attacks, where an attacker can use a modified request to escape pre-signed upload location…
Check whether django-s3file is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for django-s3file CVEs against the assets you own.
Start Free Scan →