An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.
`DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Bence Nagy for reporting this issue.
References
| Link | Resource |
|---|---|
| https://docs.djangoproject.com/en/dev/releases/security/ | Patch Vendor Advisory |
| https://groups.google.com/g/django-announce | Release Notes |
| https://www.djangoproject.com/weblog/2026/jul/07/security-releases/ | Vendor Advisory Patch |
Configurations
Configuration 1 (hide)
|
History
09 Jul 2026, 12:58
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | |
| References | () https://docs.djangoproject.com/en/dev/releases/security/ - Patch, Vendor Advisory | |
| References | () https://groups.google.com/g/django-announce - Release Notes | |
| References | () https://www.djangoproject.com/weblog/2026/jul/07/security-releases/ - Vendor Advisory, Patch | |
| First Time |
Djangoproject
Djangoproject django |
07 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-07 15:16
Updated : 2026-07-09 12:58
NVD link : CVE-2026-53878
Mitre link : CVE-2026-53878
CVE.ORG link : CVE-2026-53878
JSON object : View
Products Affected
djangoproject
- django
CWE
CWE-144
Improper Neutralization of Line Delimiters
