CVE-2025-48432
published 2025-06-05CVE-2025-48432: An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path…
medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | python-django | < python-django 3:3.2.25-0+deb12u1 (bookworm) | python-django 3:3.2.25-0+deb12u1 (bookworm) |
| djangoproject | django | >= 0 < 4.2.22 | 4.2.22 |
| djangoproject | django | >= 4.2 < 4.2.23 | 4.2.23 |
| djangoproject | django | >= 4.2 < 4.2.22 | 4.2.22 |
| djangoproject | django | >= 5.0a1 < 5.1.10 | 5.1.10 |
| djangoproject | django | >= 5.1 < 5.1.11 | 5.1.11 |
| djangoproject | django | >= 5.1 < 5.1.10 | 5.1.10 |
| djangoproject | django | >= 5.2 < 5.2.3 | 5.2.3 |
| djangoproject | django | >= 5.2 < 5.2.2 | 5.2.2 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
Red Hat
django: Django Path Injection Vulnerability
vendor_redhat·2025-06-05·CVSS 4.0
CVE-2025-48432 [MEDIUM] CWE-117 django: Django Path Injection Vulnerability
django: Django Path Injection Vulnerability
An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.
A flaw was found in Django. The `request.path` component of HTTP requests is not properly escaped when included in internal response logging, allowing remote attackers to manipulate log output through crafted URLs. This vulnerability allows an attacker to inject arbitrary content into Django's internal log files. The consequence is potential information leakage or log file corruption.
Statement: The
Ubuntu
Django vulnerability
vendor_ubuntu·2025-06-04
CVE-2025-48432 Django vulnerability
Title: Django vulnerability
Summary: Django could be made to log injection if received specially
crafted input.
It was discovered that Django incorrectly handled certain
unescaped request paths. An attacker could possibly use this
issue to perform a log injection.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2025-48432: python-django - An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 b...
vendor_debian·2025·CVSS 4.0
CVE-2025-48432 [MEDIUM] CVE-2025-48432: python-django - An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 b...
An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.
Scope: local
bookworm: resolved (fixed in 3:3.2.25-0+deb12u1)
bullseye: resolved (fixed in 2:2.2.28-1~deb11u7)
forky: resolved (fixed in 3:4.2.23-1)
sid: resolved (fixed in 3:4.2.23-1)
trixie: resolved (fixed in 3:4.2.23-1)
GHSA
Django Improper Output Neutralization for Logs vulnerability
ghsa·2025-06-05
CVE-2025-48432 [MEDIUM] CWE-117 Django Improper Output Neutralization for Logs vulnerability
Django Improper Output Neutralization for Logs vulnerability
An issue was discovered in Django 5.2 before 5.2.2, 5.1 before 5.1.10, and 4.2 before 4.2.22. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.
OSV
CVE-2025-48432: An issue was discovered in Django 5
osv·2025-06-05
CVE-2025-48432 CVE-2025-48432: An issue was discovered in Django 5
An issue was discovered in Django 5.2 before 5.2.2, 5.1 before 5.1.10, and 4.2 before 4.2.22. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.
OSV
CVE-2025-48432: An issue was discovered in Django 5
osv·2025-06-05·CVSS 5.3
CVE-2025-48432 [MEDIUM] CVE-2025-48432: An issue was discovered in Django 5
An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.
OSV
Django Improper Output Neutralization for Logs vulnerability
osv·2025-06-05
CVE-2025-48432 [MEDIUM] Django Improper Output Neutralization for Logs vulnerability
Django Improper Output Neutralization for Logs vulnerability
An issue was discovered in Django 5.2 before 5.2.2, 5.1 before 5.1.10, and 4.2 before 4.2.22. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://docs.djangoproject.com/en/dev/releases/security/https://groups.google.com/g/django-announcehttps://www.djangoproject.com/weblog/2025/jun/04/security-releases/https://www.djangoproject.com/weblog/2025/jun/10/bugfix-releases/http://www.openwall.com/lists/oss-security/2025/06/04/5http://www.openwall.com/lists/oss-security/2025/06/10/2http://www.openwall.com/lists/oss-security/2025/06/10/3http://www.openwall.com/lists/oss-security/2025/06/10/4
2025-06-05
Published