VulnerabilityAnalyzed
CVE-2025-48432
Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs.
MEDIUM 5.3EPSS 0.75%
Does this matter?
Lower severity and a low EPSS score (0.75%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.75% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-117
- Affected
- djangoproject/django · debian/debian linux
- Source
- cve@mitre.org
References
- https://docs.djangoproject.com/en/dev/releases/security/Vendor Advisory
- https://groups.google.com/g/django-announceVendor Advisory
- https://www.djangoproject.com/weblog/2025/jun/04/security-releases/Vendor Advisory
- https://www.djangoproject.com/weblog/2025/jun/10/bugfix-releases/Release Notes
- http://www.openwall.com/lists/oss-security/2025/06/04/5Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2025/06/10/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2025/06/10/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2025/06/10/4Mailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.