CVE-2026-7666

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake when `fail_silently=True`, which allows on-path network attackers to read email content via cleartext interception. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Kasper Dupont for reporting this issue.
Configurations

No configuration.

History

03 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-03 14:16

Updated : 2026-06-04 15:21


NVD link : CVE-2026-7666

Mitre link : CVE-2026-7666

CVE.ORG link : CVE-2026-7666


JSON object : View

Products Affected

No product.

CWE
CWE-319

Cleartext Transmission of Sensitive Information