IsItPatchedInstant security status for any software version
← All products

CVE-2014-0480

MEDIUM severity · CVSS 5.8 · Improper input validation
5.8CVSS MEDIUM

Summary

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL to be generated.

Impact & exploitability

Attack vectorNetwork
Attack complexity
Privileges required
User interaction
Confidentiality impact
Integrity impact
Availability impactNone
Exploit probability (EPSS)1%

AV:N/AC:M/Au:N/C:P/I:P/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: https://www.djangoproject.com/weblog/2014/aug/20/security/ ↗

Last checked: Wed, 10 Jun 2026 22:18:30 UTC