CVE-2026-42196Disclosure

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerable to relative path traversal attacks, where an attacker can use a modified request to escape pre-signed upload locations and have the Django application load files from random locations into request.FILES. Depending on how files are handled, this may lead to confidentiality and integrity issues. This vulnerability is fixed in 7.0.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-26

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-28); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-28: 1Mentions · 2026-05-12: 1Technical Details · 2026-04-28: 1Technical Details · 2026-05-12: 104-2805-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Santos Gallegos@stsewd
    Disclosure

    Last year I wasn't very active reporting vulns outside work. This year I have reported 2 vulns to open source projects, one pending disclosure, and the other one was made public today. CVE-2026-42196 path traversal in django-s3file. Thanks to the maintainers for the quick action!

    Post summary

    The author announces the public disclosure of CVE‑2026‑42196, a path‑traversal vulnerability in django‑s3file, highlighting the maintainers’ swift response.

    2003097
    290 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42196 django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerable to relative path traversal attacks, where an… https://www.cve.org/CVERecord?id=CVE-2026-42196

    Post summary

    CVE-2026-42196 identifies a relative path traversal flaw in django‑s3file’s S3FileMiddleware before version 7.0.2, with no evidence of active exploitation, PoC, or patch guidance provided.

    0000080
    57.5K followersView on X

Explore more