Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2023-31047 python-django: Potential bypass of validation when uploading multiple files using one form fieldCVE-2025-64459 django: Django SQL injectionCVE-2022-41323 python-django: Potential denial-of-service vulnerability in internationalized URLsCVE-2023-23969 python-django: Potential denial-of-service via Accept-Language headersCVE-2023-24580 python-django: Potential denial-of-service vulnerability in file uploadsCVE-2023-36053 python-django: Potential regular expression denial of service vulnerability in EmailValidator/URLValidatorCVE-2023-43665 python-django: Denial-of-service possibility in django.utils.text.TruncatorCVE-2023-46695 python-django: Potential denial of service vulnerability in UsernameField on WindowsCVE-2025-57833 django: Django SQL injection in FilteredRelation column aliasesCVE-2025-64458 Django: Denial-of-service vulnerability in Django on WindowsCVE-2023-41164 python-django: Potential denial of service vulnerability in ``django.utils.encoding.uri_to_iri()``CVE-2024-45231 python-django: Potential user email enumeration via response status on password resetCVE-2025-48432 django: Django Path Injection VulnerabilityCVE-2026-53877 django: Django: Information disclosure via heap buffer over-read in GDALRasterCVE-2026-53878 django: Django: HTTP header injection via DomainNameValidator accepting newlinesCVE-2024-4340 sqlparse: parsing heavily nested list leads to denial of serviceCVE-2023-30608 sqlparse: Parser contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service)GHSA-27jp-wm6q-gp25 sqlparse: formatting list of tuples leads to denial of serviceCVE-2026-48587 django: Django: Information disclosure via improper handling of Vary header whitespaceCVE-2026-48588 django: Django: Information disclosure due to improper caching of Set-Cookie responsesCVE-2026-6873 python-django: Django: Information disclosure via non-injective cookie salt derivationCVE-2026-8404 Django: Django: Information disclosure due to improper handling of Cache-Control directivesYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2026-2120 Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use fromPYSEC-2023-61 In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supporGHSA-frmv-pr5f-9mcr Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.PYSEC-2024-48 Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_expanded function in the strings.py file. An attacker could ePYSEC-2026-2121 Black is the uncompromising Python code formatter. Prior to 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics optiPYSEC-2026-2132 Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.PYSEC-2022-304 In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regularPYSEC-2023-100 In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large numbPYSEC-2023-12 In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-sPYSEC-2023-13 An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart fPYSEC-2023-222 An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.forms.UsernameField is suPYSEC-2023-225 In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large nPYSEC-2023-226 In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of sPYSEC-2026-1297 Django allows enumeration of user e-mail addressesGHSA-6w2r-r2m5-xq5w Django is subject to SQL injection through its column aliasesGHSA-7xr5-9hcq-chf9 Django Improper Output Neutralization for Logs vulnerabilityGHSA-8qcx-xf44-272x Django: DomainNameValidator permits newline characters that may enable HTTP header injectionGHSA-crhf-3pfg-w68w Django: GDALRaster may over-read heap memory when constructed from bytesGHSA-qw25-v68c-qjf3 Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on WindowsPYSEC-2023-87 sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This isPYSEC-2026-1940 sqlparse parsing heavily nested list leads to Denial of ServiceGHSA-27jp-wm6q-gp25 sqlparse: formatting list of tuples leads to denial of serviceGHSA-3h9f-r86x-qvjx Django: cache middleware may expose private responses when unrelated request cookies are presentGHSA-8cjm-8mp7-r2xf Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handlingGHSA-923m-gv2p-w5qp Django: has_vary_header may expose cached responses when Vary values contain whitespaceCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.