Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2021-35042 django: potential SQL injection via unsanitized QuerySet.order_by() inputCVE-2025-64459 django: Django SQL injectionCVE-2021-31542 django: Potential directory-traversal via uploaded filesCVE-2021-33571 django: Possible indeterminate SSRF, RFI, and LFI attacks since validators accepted leading zeros in IPv4 addressesCVE-2022-36359 An issue was discovered in the HTTP FileResponse class in Django 3.2 b ...CVE-2025-57833 django: Django SQL injection in FilteredRelation column aliasesCVE-2025-64458 Django: Denial-of-service vulnerability in Django on WindowsCVE-2021-28658 django: potential directory-traversal via uploaded filesCVE-2021-32052 django: header injection possibility since URLValidator accepted newlines in input on Python 3.9.5+CVE-2021-3281 django: Potential directory-traversal via archive.extract()CVE-2021-33203 django: Potential directory traversal via ``admindocs``CVE-2021-44420 django: potential bypass of an upstream access control based on URL pathsCVE-2024-45231 python-django: Potential user email enumeration via response status on password resetCVE-2025-48432 django: Django Path Injection VulnerabilityCVE-2026-53877 django: Django: Information disclosure via heap buffer over-read in GDALRasterCVE-2026-53878 django: Django: HTTP header injection via DomainNameValidator accepting newlinesCVE-2021-23727 celery: stored command injection vulnerability may allow privileges escalationCVE-2024-1135 python-gunicorn: HTTP Request Smuggling due to improper validation of Transfer-Encoding headersCVE-2024-6827 gunicorn: HTTP Request Smuggling in benoitc/gunicornCVE-2026-28684 python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link followingCVE-2026-48587 django: Django: Information disclosure via improper handling of Vary header whitespaceCVE-2026-48588 django: Django: Information disclosure due to improper caching of Set-Cookie responsesCVE-2026-6873 python-django: Django: Information disclosure via non-injective cookie salt derivationCVE-2026-8404 Django: Django: Information disclosure due to improper handling of Cache-Control directivesCVE-2024-21520 djangorestframework: Cross-site Scripting (XSS) via break_long_headersYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2021-109 Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.GHSA-frmv-pr5f-9mcr Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.PYSEC-2021-109 Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.GHSA-frmv-pr5f-9mcr Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.PYSEC-2021-109 Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.GHSA-frmv-pr5f-9mcr Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.PYSEC-2024-187 virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same PYSEC-2021-439 In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.PYSEC-2021-6 In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were notPYSEC-2021-7 In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.PYSEC-2021-8 In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application PYSEC-2021-9 In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal vPYSEC-2021-98 Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existPYSEC-2021-99 In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This maPYSEC-2026-1297 Django allows enumeration of user e-mail addressesGHSA-6w2r-r2m5-xq5w Django is subject to SQL injection through its column aliasesGHSA-7xr5-9hcq-chf9 Django Improper Output Neutralization for Logs vulnerabilityGHSA-8qcx-xf44-272x Django: DomainNameValidator permits newline characters that may enable HTTP header injectionGHSA-8x94-hmjh-97hq Django vulnerable to Reflected File Download attackGHSA-crhf-3pfg-w68w Django: GDALRaster may over-read heap memory when constructed from bytesGHSA-qw25-v68c-qjf3 Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on WindowsPYSEC-2021-858 This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. PYSEC-2026-1304 Cross-site Scripting in djangorestframeworkPYSEC-2026-1433 Gunicorn HTTP Request/Response Smuggling vulnerabilityPYSEC-2026-1434 Request smuggling leading to endpoint restriction bypass in GunicornCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.