
6 CVEs in Django https://www.openwall.com/lists/oss-security/2026/02/03/1 CVE-2025-13473: Username enumeration through timing difference in mod_wsgi authentication handler CVE-2025-14550: Potential DoS via repeated headers when using ASGI CVE-2026-1207: Potential SQL injection via raster lookups on PostGIS
Post summary
Three new Django CVEs were disclosed, covering username enumeration, DoS via repeated headers, and SQL injection through PostGIS raster lookups.



