SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-48432

Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs.

MEDIUM 5.3EPSS 0.75%

Does this matter?

Lower severity and a low EPSS score (0.75%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
0.75% probability · 53th percentile
CISA KEV
Not listed
Weakness
CWE-117
Affected
djangoproject/django · debian/debian linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.