CVE-2026-25674Disclosure(djangoproject / django)

LOWCVSS 3.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch djangoproject django systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's temporary `umask` change affects other threads in multi-threaded environments. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • django

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-03); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Products
django

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-03: 4Mentions · 2026-03-08: 1Patch / Workaround · 2026-03-08: 1Technical Details · 2026-03-03: 4Technical Details · 2026-03-08: 103-0303-08
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-034
Disclosure4
2026-03-081
Patch1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Patch

    2 CVEs fixed in Django https://www.openwall.com/lists/oss-security/2026/03/03/3 CVE-2026-25673: DoS in URLField via Unicode normalization on Windows CVE-2026-25674: Potential incorrect permissions on newly created file system objects in multi-threaded environments

    Post summary

    The update announces that two Django CVEs have been fixed, providing brief technical details and a link to the advisory.

    00020323
    4.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25674 An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django a… https://www.cve.org/CVERecord?id=CVE-2026-25674

    Post summary

    A race condition vulnerability (CVE-2026-25674) affecting Django file‑system storage and cache backends was disclosed, with affected versions listed but no exploitation or patch details provided.

    00011181
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25674 Race Condition in Django File-System Storage Causing Incorrect Permissions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25674

    Post summary

    A race condition in Django’s file‑system storage leads to incorrect permissions, as disclosed in CVE‑2026‑25674.

    0001060
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-25674 - Potential incorrect permissions on newly created file system objects Intel Report: https://ift.tt/HNCs5O9

    Post summary

    The alert announces CVE-2026-25674, highlighting a potential incorrect permissions issue on newly created file system objects, with no PoC, exploit, or patch details provided.

    0000041
    342 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25674 An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django a… https://www.cve.org/CVERecord?id=CVE-2026-25674 ----- Traducción: CVE-2026-25674 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-25674, a race condition in Django’s file‑system storage and cache backends, detailing affected versions but providing no PoC, exploit, or patch information.

    0000029
    55 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdjangoprojectdjango---

Explore more