
Find real vulnerabilities before they ship
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
Base Score
7.3| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| Django(PyPI) | 2.2a1 | 2.2.25 | N/A |
| Django(PyPI) | 3.0a1 | 3.1.14 | N/A |
| Django(PyPI) | 3.2a1 | 3.2.10 | N/A |
| Base Score | 7.3 |
|---|---|
| Vector String | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
| Base Severity | High |
| Version | 3.1 |
| Attack Vector (AV) | NETWORK |