CVE-2018-1000089
published 2018-03-13CVE-2018-1000089: Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An…
PriorityP339high7.4CVSS 3.0
AVNACHPRNUINSUCHIHAN
EPSS
1.24%
66.2th percentile
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | django-anymail | < django-anymail 1.4-1 (bookworm) | django-anymail 1.4-1 (bookworm) |
| django-anymail_project | django-anymail | >= 0 < 1.4-1 | 1.4-1 |
| django-anymail_project | django-anymail | >= 0 < 1.4-1 | 1.4-1 |
| django-anymail_project | django-anymail | >= 0 < 1.4-1 | 1.4-1 |
| django-anymail_project | django-anymail | >= 0 < 1.4-1 | 1.4-1 |
| django-anymail_project | django-anymail | >= 0.2 < 1.4 | 1.4 |
| django-anymail_project | django-anymail | 0.2 – 1.3 | — |
CVSS provenance
nvdv3.07.4HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.4HIGH
vendor_debian7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
django-anymail Includes Sensitive Information in Log Files
ghsa·2022-05-14
CVE-2018-1000089 [CRITICAL] CWE-532 django-anymail Includes Sensitive Information in Log Files
django-anymail Includes Sensitive Information in Log Files
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4.
OSV
django-anymail Includes Sensitive Information in Log Files
osv·2022-05-14
CVE-2018-1000089 [CRITICAL] django-anymail Includes Sensitive Information in Log Files
django-anymail Includes Sensitive Information in Log Files
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4.
OSV
CVE-2018-1000089: Anymail django-anymail version version 0
osv·2018-03-13·CVSS 7.4
CVE-2018-1000089 [HIGH] CVE-2018-1000089: Anymail django-anymail version version 0
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4.
Debian
CVE-2018-1000089: django-anymail - Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-2...
vendor_debian·2018·CVSS 7.4
CVE-2018-1000089 [HIGH] CVE-2018-1000089: django-anymail - Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-2...
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4.
Scope: local
bookworm: resolved (fixed in 1.4-1)
bullseye: resolved (fixed in 1.4-1)
forky: resolved (fixed in 1.4-1)
sid: resolved (fixed in 1.4-1)
trixie: resolved (fixed in 1.4-1)
No detection rules found.
No public exploits indexed.
arXiv
AgenticSCR: An Autonomous Agentic Secure Code Review for Immature Vulnerabilities Detection
arxiv_fulltext·2026-01-27
AgenticSCR: An Autonomous Agentic Secure Code Review for Immature Vulnerabilities Detection
AgenticSCR: An Autonomous Agentic Secure Code Review for Immature Vulnerabilities Detection
Wachiraphan Charoenwet
The University of Melbourne
Australia.
Kla Tantithamthavorn
Monash University
Australia.
Patanamon Thongtanunam
The University of Melbourne
Australia.
Hong Yi Lin
The University of Melbourne
Australia.
Minwoo Jeong
Atlassian
USA.
Ming Wu
Atlassian
USA.
## Abstract
Secure code review is critical at the pre-commit stage, where vulnerabilities must be caught early under tight latency and limited-context constraints.
Existing SAST-based checks are noisy and often miss immature, context-dependent vulnerabilities, while standalone Large Language Models (LLMs) are constrained by context windows and lack explicit tool use.
Agentic AI, which combine LLMs with autonomous d
arXiv
Evaluating LLMs for One-Shot Patching of Real and Artificial Vulnerabilities
arxiv_fulltext·2025-11-28
Evaluating LLMs for One-Shot Patching of Real and Artificial Vulnerabilities
Evaluating LLMs for One-Shot Patching of Real and Artificial Vulnerabilities
Aayush Garg
[email protected]
0000-0002-2507-8846
Luxembourg Institute of Science and Technology
Luxembourg
Zanis Ali Khan
[email protected]
0000-0002-3935-2148
Luxembourg Institute of Science and Technology
Luxembourg
Renzo Degiovanni
[email protected]
0000-0003-1611-3969
Luxembourg Institute of Science and Technology
Luxembourg
Qiang Tang
[email protected]
0000-0002-6153-4255
Luxembourg Institute of Science and Technology
Luxembourg
## Abstract
Automated vulnerability patching is crucial for software security, and recent advancements in Large Language Models (LLMs) present promising capabilities for automating this task. However, existing research has primarily assessed LLMs using public
2018-03-13
Published