
Last year I wasn't very active reporting vulns outside work. This year I have reported 2 vulns to open source projects, one pending disclosure, and the other one was made public today. CVE-2026-42196 path traversal in django-s3file. Thanks to the maintainers for the quick action!
Post summary
The author announces the public disclosure of CVE‑2026‑42196, a path‑traversal vulnerability in django‑s3file, highlighting the maintainers’ swift response.

