CVE-2026-53878

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*

History

09 Jul 2026, 12:58

Type Values Removed Values Added
CPE cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
References () https://docs.djangoproject.com/en/dev/releases/security/ - () https://docs.djangoproject.com/en/dev/releases/security/ - Patch, Vendor Advisory
References () https://groups.google.com/g/django-announce - () https://groups.google.com/g/django-announce - Release Notes
References () https://www.djangoproject.com/weblog/2026/jul/07/security-releases/ - () https://www.djangoproject.com/weblog/2026/jul/07/security-releases/ - Vendor Advisory, Patch
First Time Djangoproject
Djangoproject django

07 Jul 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-07 15:16

Updated : 2026-07-09 12:58


NVD link : CVE-2026-53878

Mitre link : CVE-2026-53878

CVE.ORG link : CVE-2026-53878


JSON object : View

Products Affected

djangoproject

  • django
CWE
CWE-144

Improper Neutralization of Line Delimiters