
5 CVEs fixed in Django https://www.openwall.com/lists/oss-security/2026/04/07/10 CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable + next tweet
Post summary
The tweet announces that five Django CVEs have been fixed, providing concise technical descriptions for three of them, but offers no exploit or PoC details.


