
5 CVEs fixed in Django https://www.openwall.com/lists/oss-security/2026/04/07/10 CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable + next tweet
Post summary
The post announces that five Django CVEs have been fixed, providing brief technical descriptions of three of them, confirming that patches are available.


