PT-2026-22742 · Django+1 · Django+1

Natalia Bidart

+1

·

Published

2026-03-03

·

Updated

2026-05-13

·

CVE-2026-25674

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Django versions 4.2 before 4.2.29 Django versions 5.2 before 5.2.12 Django versions 6.0 before 6.0.3 Django versions 3.2.x and earlier Django versions 4.1.x and earlier Django versions 5.0.x and earlier
Description A race condition exists in Django's file-system storage and file-based cache backends. This condition can lead to the creation of file system objects with incorrect permissions when concurrent requests are processed in multi-threaded environments. Specifically, a temporary umask change made by one thread can affect other threads, resulting in unintended file permissions. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) may also be affected.
Recommendations Update Django to version 4.2.29 or later. Update Django to version 5.2.12 or later. Update Django to version 6.0.3 or later. Update Django to a version later than 3.2.x. Update Django to a version later than 4.1.x. Update Django to a version later than 5.0.x.

Fix

Race Condition

Weakness Enumeration

Related Identifiers

BIT-DJANGO-2026-25674
CVE-2026-25674
GHSA-MJGH-79QC-68W3
MGASA-2026-0050
OESA-2026-1506
OESA-2026-1508
OESA-2026-1509
OESA-2026-1510
OESA-2026-1511
OESA-2026-2216
OPENSUSE-SU-2026:10282-1
OPENSUSE-SU-2026:10283-1
OPENSUSE-SU-2026:10292-1
OPENSUSE-SU-2026:20373-1
SUSE-SU-2026:0821-1

Affected Products

Django
Red Os