CVE-2026-7666

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake when `fail_silently=True`, which allows on-path network attackers to read email content via cleartext interception. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Kasper Dupont for reporting this issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*

History

21 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en Django 6.0 anterior a 6.0.6 y 5.2 anterior a 5.2.15. 'django.core.mail.backends.smtp.EmailBackend' en Django falla al evitar la reutilización de una conexión parcialmente inicializada después de un handshake 'STARTTLS' fallido cuando 'fail_silently=True', lo que permite a atacantes de red en la ruta leer el contenido del correo electrónico mediante intercepción de texto claro. Series de Django anteriores no soportadas (como 5.0.x, 4.1.x y 3.2.x) no fueron evaluadas y también podrían estar afectadas. Django desea agradecer a Kasper Dupont por reportar este problema.

05 Jun 2026, 12:46

Type Values Removed Values Added
First Time Djangoproject
Djangoproject django
References () https://docs.djangoproject.com/en/dev/releases/security/ - () https://docs.djangoproject.com/en/dev/releases/security/ - Patch, Vendor Advisory
References () https://groups.google.com/g/django-announce - () https://groups.google.com/g/django-announce - Release Notes
References () https://www.djangoproject.com/weblog/2026/jun/03/security-releases/ - () https://www.djangoproject.com/weblog/2026/jun/03/security-releases/ - Patch, Vendor Advisory
CPE cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*

03 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-03 14:16

Updated : 2026-07-21 19:10


NVD link : CVE-2026-7666

Mitre link : CVE-2026-7666

CVE.ORG link : CVE-2026-7666


JSON object : View

Products Affected

djangoproject

  • django
CWE
CWE-319

Cleartext Transmission of Sensitive Information