CVE-2026-1285General(djangoproject / django)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch djangoproject django systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.chars()` and `Truncator.words()` methods (with `html=True`) and the `truncatechars_html` and `truncatewords_html` template filters allow a remote attacker to cause a potential denial-of-service via crafted inputs containing a large number of unmatched HTML end tags. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-407

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • django

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-03); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
django

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-03: 1Mentions · 2026-02-06: 1Mentions · 2026-02-08: 1Patch / Workaround · 2026-02-08: 1Technical Details · 2026-02-08: 102-0302-0602-08
Signal classification2 categories
General
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-031
General1
2026-02-061
General1
2026-02-081
Patch1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Patch

    More of the CVEs fixed in Django: CVE-2026-1285: Potential DoS in django.utils.text.Truncator HTML methods CVE-2026-1287: Potential SQL injection in column aliases via control characters CVE-2026-1312: Potential SQL injection via QuerySet.order_by and FilteredRelation

    Post summary

    The message lists several Django CVEs that have been fixed, describing potential DoS and SQL injection vulnerabilities and indicating that patches are available.

    00040377
    4.4K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en Django ❗ CVE-2026-1285 ❗ CVE-2025-14550 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-django/ https://t.co/2yWYGFJhBu

    Post summary

    The tweet lists two Django CVEs and directs readers to external links for additional information.

    00000116
    6.6K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-1285 An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.chars()` and `Truncator.words()` methods (with `html… https://www.cve.org/CVERecord?id=CVE-2026-1285

    Post summary

    CVE-2026-1285 is a vulnerability affecting specific Django versions, with no further details on exploitation, patches, or technical specifics provided.

    00000163
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdjangoprojectdjango---

Explore more