CVE-2025-48432
MEDIUM severity · CVSS 4 · CWE-117
4CVSS MEDIUM
Summary
An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.
Impact & exploitability
Attack vectorNetwork
Attack complexityHigh
Privileges requiredNone
User interactionNone
Confidentiality impactNone
Integrity impactLow
Availability impactNone
Exploit probability (EPSS)1%
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- https://docs.djangoproject.com/en/dev/releases/security/Advisory
- https://groups.google.com/g/django-announceAdvisory
- https://www.djangoproject.com/weblog/2025/jun/04/security-releases/Advisory
- https://www.djangoproject.com/weblog/2025/jun/10/bugfix-releases/
- http://www.openwall.com/lists/oss-security/2025/06/04/5Advisory
- http://www.openwall.com/lists/oss-security/2025/06/10/2Advisory
- http://www.openwall.com/lists/oss-security/2025/06/10/3Advisory
- http://www.openwall.com/lists/oss-security/2025/06/10/4