djangorestframework
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting djangorestframeworkpage 1 of 1
- CVE-2020-25626MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.11.22020-09-30
vulnerable: 0.1 ... 3.9.4 (125 versions)
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who …
- CVE-2024-21520MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.15.22024-06-26
vulnerable: 0.1 ... 3.9.4 (136 versions)
Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags.
Check whether djangorestframework is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for djangorestframework CVEs against the assets you own.
Start Free Scan →