THE Django team released updates (versions 6.0.8 and 5.2.17) addressing four vulnerabilities, notably CVE-2026-15307, which could enable remote code execution in certain setups. Users are urged to upgrade immediately. CVE-2026-15307 has a high severity score of 8.8 (CVSSv3) and can lead to server-side file writes and request forgery. Other vulnerabilities include potential denial-of-service and cross-site scripting issues. There is no confirmed exploitation of these vulnerabilities, and patches are available to mitigate risks.
Django patches high severity CVE-2026-15307, urges upgrade
CyberSIXT Evidence Panel
Article by CyberSIXT