In-app reader
__ CVE-2026-25674 Detail
An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29.
Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's temporary umask change affects other threads in multi-threaded environments.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Tarek Nakkouch for reporting this issue.
**CVSS Version 4.0
**CVSS Version 3.x
**CVSS Version 2.0
_
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
_
CVSS 4.0 Severity and Vector Strings:
NIST: NVD
** ** N/A
NVD assessment not yet provided. _
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base Score: N/A
NVD assessment not yet provided. _
ADP: CISA-ADP
Base Score: 3.7 LOW
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N _
CVSS 2.0 Severity and Vector Strings:
NIST: NVD
Base Score: N/A
NVD assessment not yet provided. _
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].
URL Source(s) Tag(s)
https://docs.djangoproject.com/en/dev/releases/security/
Django Software Foundation
Patch
Vendor Advisory
https://groups.google.com/g/django-announce
Django Software Foundation
Release Notes
https://www.djangoproject.com/weblog/2026/mar/03/security-releases/
Django Software Foundation
Patch
Vendor Advisory
CWE-ID CWE Name Source
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Django Software Foundation
Known Affected Software Configurations Switch to CPE 2.2
_
_ _
__ Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
5 change records found show changes
** CVE Modified by CISA-ADP 6/17/2026 6:25:02 AM **
Action Type Old Value New Value
Added SSVC
{"timestamp":"2026-03-03T15:27:07.815602Z","id":"CVE-2026-25674","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}
** CVE Modified by Django Software Foundation 6/17/2026 6:25:02 AM **
Action Type Old Value New Value
Added Affected
[{"vendor":"djangoproject","product":"Django","defaultStatus":"unaffected","collectionURL":"https://pypi.org/project/Django/","packageName":"django","repo":"https://github.com/django/django/","versions":[{"version":"6.0","lessThan":"6.0.3","versionType":"semver","status":"affected"},{"version":"6.0.3","versionType":"semver","status":"unaffected"},{"version":"5.2","lessThan":"5.2.12","versionType":"semver","status":"affected"},{"version":"5.2.12","versionType":"semver","status":"unaffected"},{"version":"4.2","lessThan":"4.2.29","versionType":"semver","status":"affected"},{"version":"4.2.29","versionType":"semver","status":"unaffected"}]}]
** Initial Analysis by NIST 3/05/2026 9:07:03 AM **
Action Type Old Value New Value
Added CPE Configuration
OR
*cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* versions from (including) 4.2.0 up to (excluding) 4.2.29
*cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* versions from (including) 5.2 up to (excluding) 5.2.12
*cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* versions from (including) 6.0 up to (excluding) 6.0.3
Added Reference Type
Django Software Foundation: https://docs.djangoproject.com/en/dev/releases/security/ Types: Patch, Vendor Advisory
Added Reference Type
Django Software Foundation: https://groups.google.com/g/django-announce Types: Release Notes
Added Reference Type
Django Software Foundation: https://www.djangoproject.com/weblog/2026/mar/03/security-releases/ Types: Patch, Vendor Advisory
** CVE Modified by CISA-ADP 3/03/2026 11:16:21 AM **
Action Type Old Value New Value
Added CVSS V3.1
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
** New CVE Received from Django Software Foundation 3/03/2026 10:16:19 AM **
Action Type Old Value New Value
Added Description
An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29.
Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's temporary `umask` change affects other threads in multi-threaded environments.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Tarek Nakkouch for reporting this issue.
Added CWE
CWE-362
Added Reference
https://docs.djangoproject.com/en/dev/releases/security/
Added Reference
https://groups.google.com/g/django-announce
Added Reference
https://www.djangoproject.com/weblog/2026/mar/03/security-releases/
Quick Info
CVE Dictionary Entry: CVE-2026-25674 NVD Published Date: 03/03/2026 NVD Last Modified: 06/17/2026 ** Source:** Django Software Foundation
_
Discussion
Sign in to join the discussion.
Keep reading
Optional: create a free account to save items, track programs, and sync across web + app. Reading stays free.