CyberRota Analysis
AI-GeneratedThe vulnerability affects Django versions 6.0 prior to 6.0.7 and 5.2 prior to 5.2.16, specifically in the `DomainNameValidator`, which fails to restrict newlines in domain names, potentially leading to HTTP response header injection if newlines are included in application values. While Django's `HttpResponse` mitigates this risk by prohibiting newlines in headers, applications utilizing affected versions should prioritize patching to prevent exploitation. Developers and organizations using these Django versions should assess their applications for this vulnerability, especially if they handle domain names dynamically.
Original NVD Description
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)