A AegiFlow
MEDIUMCVSS 5.3EPSS 0.2%

CVE-2026-53878

Django: DomainNameValidator permits newline characters that may enable HTTP header injection

Published
2026-07-07
Modified
2026-08-07
EPSS percentile
11%
Aliases
GHSA-8qcx-xf44-272x
Sources
github-advisory

Summary

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIdjango5.2.16, 6.0.7

Remediation: Upgrade to 5.2.16 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.