Skip to content

fix(deps): vuln Django (major → 6.1) [python/django/django-realworld/django-realworld-example-app/requirements.txt] - #242

Open
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/major/pip/django-realworld-example-app/3-1788172115
Open

fix(deps): vuln Django (major → 6.1) [python/django/django-realworld/django-realworld-example-app/requirements.txt]#242
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/major/pip/django-realworld-example-app/3-1788172115

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor

Summary: Critical-severity security update — 1 package upgraded (MAJOR changes included)

Manifests changed:

  • python/django/django-realworld/django-realworld-example-app/requirements.txt (pip)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
Django 1.10.5 6.1 major Direct 9 CRITICAL, 9 HIGH, 26 MEDIUM, 12 LOW

Warning

Major Version Upgrade

This update includes major version changes that may contain breaking changes. Please:

  • Review the changelog/release notes for breaking changes
  • Test thoroughly in a staging environment
  • Update any code that depends on changed APIs
  • Ensure all tests pass before merging

Security Details

🚨 Critical & High Severity (18 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
Django CVE-2020-7471 CRITICAL - 1.10.5 - -
Django GHSA-hmr4-m2h5-33qx CRITICAL SQL injection in Django 1.10.5 1.11.28 -
Django PYSEC-2019-16 CRITICAL - 1.10.5 1.11.27 -
Django CVE-2019-19844 CRITICAL - 1.10.5 - -
Django CVE-2025-64459 CRITICAL Potential SQL injection via _connector keyword argument in QuerySet and Q objects 1.10.5 - -
Django PYSEC-2020-35 CRITICAL - 1.10.5 eb31d845323618d688ad429479c6dda973056136 -
Django GHSA-vfq6-hq5r-27r6 CRITICAL Django Potential account hijack via password reset form 1.10.5 1.11.27 -
Django GHSA-frmv-pr5f-9mcr CRITICAL Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects. 1.10.5 5.2.8 -
Django PYSEC-2025-108 CRITICAL - 1.10.5 4.2.26 -
Django PYSEC-2025-107 HIGH - 1.10.5 4.2.26 -
Django CVE-2025-64458 HIGH Potential denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows 1.10.5 - -
Django PYSEC-2022-245 HIGH - 1.10.5 3.2.15 -
Django GHSA-6w2r-r2m5-xq5w HIGH Django is subject to SQL injection through its column aliases 1.10.5 4.2.24 -
Django CVE-2025-57833 HIGH - 1.10.5 - -
Django PYSEC-2025-105 HIGH - 1.10.5 4.2.24 -
Django CVE-2022-36359 HIGH - 1.10.5 - -
Django GHSA-8x94-hmjh-97hq HIGH Django vulnerable to Reflected File Download attack 1.10.5 3.2.15 -
Django GHSA-qw25-v68c-qjf3 HIGH Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows 1.10.5 5.2.8 -
ℹ️ Other Vulnerabilities (38)
Package CVE Severity Summary Unsafe Version Fixed In Case
Django PYSEC-2017-9 medium - 1.10.5 1.10.7 -
Django PYSEC-2026-3717 medium - 1.10.5 5.2.17 -
Django CVE-2026-15830 medium Potential denial-of-service vulnerability via nested geometry collections 1.10.5 - -
Django CVE-2021-33203 medium - 1.10.5 - -
Django PYSEC-2021-98 medium - 1.10.5 2.2.24 -
Django CVE-2017-7233 medium - 1.10.5 - -
Django GHSA-37hp-765x-j95x MODERATE Django open redirect and possible XSS attack via user-supplied numeric redirect URLs 1.10.5 1.10.7 -
Django GHSA-68w8-qjq3-2gfm MODERATE Path Traversal in Django 1.10.5 2.2.24 -
Django PYSEC-2026-1297 MODERATE Django allows enumeration of user e-mail addresses 1.10.5 4.2.16 -
Django GHSA-rrqc-c2jx-6jgv MODERATE Django allows enumeration of user e-mail addresses 1.10.5 5.1.1 -
Django PYSEC-2017-44 MODERATE - 1.10.5 1.10.8 -
Django CVE-2017-12794 MODERATE - 1.10.5 - -
Django GHSA-9r8w-6x8c-6jr9 MODERATE Django vulnerable to XSS on 500 pages 1.10.5 1.10.8 -
Django GHSA-h4hv-m4h4-mhwg MODERATE Django open redirect 1.10.5 1.10.7 -
Django PYSEC-2026-2091 MODERATE - 1.10.5 5.2.16 -
Django CVE-2026-53877 MODERATE Heap buffer over-read in GDALRaster 1.10.5 - -
Django GHSA-crhf-3pfg-w68w MODERATE Django: GDALRaster may over-read heap memory when constructed from bytes 1.10.5 5.2.16 -
Django PYSEC-2026-2092 MODERATE - 1.10.5 5.2.16 -
Django CVE-2026-53878 MODERATE Header injection possibility since DomainNameValidator accepted newlines in input 1.10.5 - -
Django GHSA-8qcx-xf44-272x MODERATE Django: DomainNameValidator permits newline characters that may enable HTTP header injection 1.10.5 5.2.16 -
Django CVE-2017-7234 MODERATE - 1.10.5 - -
Django CVE-2024-45231 MODERATE - 1.10.5 - -
Django PYSEC-2017-10 MODERATE - 1.10.5 1.10.7 -
Django GHSA-7xr5-9hcq-chf9 MODERATE Django Improper Output Neutralization for Logs vulnerability 1.10.5 5.2.2 -
Django CVE-2025-48432 MODERATE - 1.10.5 - -
Django PYSEC-2025-47 MODERATE - 1.10.5 5.2.2 -
Django GHSA-3h9f-r86x-qvjx LOW Django: cache middleware may expose private responses when unrelated request cookies are present 1.10.5 5.2.16 -
Django CVE-2026-48588 LOW Potential exposure of private data via cached Set-Cookie response 1.10.5 - -
Django PYSEC-2026-2090 LOW - 1.10.5 5.2.16 -
Django GHSA-h7pc-vwp9-298g LOW Django: signed cookies are vulnerable to salt namespace collisions 1.10.5 5.2.15 -
Django PYSEC-2026-198 LOW - 1.10.5 5.2.15 -
Django CVE-2026-48587 LOW Potential exposure of private data via whitespace padding in Vary header 1.10.5 - -
Django GHSA-923m-gv2p-w5qp LOW Django: has_vary_header may expose cached responses when Vary values contain whitespace 1.10.5 5.2.15 -
Django CVE-2026-6873 LOW Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie 1.10.5 - -
Django PYSEC-2026-199 LOW - 1.10.5 5.2.15 -
Django PYSEC-2026-201 LOW - 1.10.5 5.2.15 -
Django CVE-2026-8404 LOW Potential exposure of private data via case-sensitive Cache-Control directives in UpdateCacheMiddleware 1.10.5 - -
Django GHSA-8cjm-8mp7-r2xf LOW Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling 1.10.5 5.2.15 -

Review Checklist

Extra review is recommended for this update:

  • Review changes for compatibility with your code
  • Check release notes for breaking changes
  • Run integration tests to verify service behavior
  • Test in staging environment before production
  • Monitor key metrics after deployment
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants