Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.1 CVE-2026-8404

Potential exposure of private data via case-sensitive Cache-Control directives in UpdateCacheMiddleware_CVE-2026-8404

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match ...

djangoproject Django 6.0 CVE
LOW 3.1 CVE-2026-7666

Potential unencrypted email transmission via STARTTLS in the SMTP backend_CVE-2026-7666

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent ...

djangoproject Django 6.0 CVE
LOW 3.1 CVE-2026-6873

Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie_CVE-2026-6873

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injectiv...

djangoproject Django 6.0 CVE
LOW 3.1 CVE-2026-48587

Potential exposure of private data via whitespace padding in Vary header_CVE-2026-48587

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading o...

djangoproject Django 6.0 CVE
LOW 3.7 CVE-2026-44546

Header injection via WebSocket upgrade parser differential allows ASGI scope header spoofing_CVE-2026-44546

daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processing. Twis...

djangoproject daphne 4.2.0 CVE
LOW 3.1 CVE-2026-35193

Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddleware_CVE-2026-35193

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `A...

djangoproject Django 6.0 CVE
LOW 1.2 CVE-2026-10729

HTML injection in the notification email for “Slow Redirect” and “Cloned Website” Canarytokens_CVE-2026-10729

An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research ...

Thinkst Applied Research Canarytokens sha-c42435e CVE
LOW 2.3 CVE-2026-50052

CVE-2026-50052_CVE-2026-50052

In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request des...

The Vinyl Cache Project Vinyl Cache 9.0.0 CVE
LOW 2.3 CVE-2026-10705

dask HLL hyperloglog.py nunique_approx resource consumption_CVE-2026-10705

A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the com...

n/a dask 3.0 CVE
LOW 1.8 CVE-2026-10717

Open-Seachest/Seachest show SCSI Defect List Vulnerability_CVE-2026-10717

Out of bounds write and reads in openSeaChest’s --showSCSIDefects in Seagate’s openSeaChest v25.05.3 on all supported platforms allows for writing ...

N/A N/A 26.03.0 CVE