AUGUST 27, 2026
Live Feed
Back to database
Case File

CVE-2026-53878

MEDIUM · CVSS 6.1 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

The vulnerability affects Django versions 6.0 prior to 6.0.7 and 5.2 prior to 5.2.16, specifically in the `DomainNameValidator`, which fails to restrict newlines in domain names, potentially leading to HTTP response header injection if newlines are included in application values. While Django's `HttpResponse` mitigates this risk by prohibiting newlines in headers, applications utilizing affected versions should prioritize patching to prevent exploitation. Developers and organizations using these Django versions should assess their applications for this vulnerability, especially if they handle domain names dynamically.

CVE
CVE-2026-53878
Severity
MEDIUM
CVSS
6.1
EPSS
0.21%

Original NVD Description

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)