Medium severity6.1NVD Advisory· Published May 6, 2021· Updated Jun 17, 2026
CVE-2021-32052
CVE-2021-32052
Description
In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
DjangoPyPI | >= 2.2, < 2.2.22 | 2.2.22 |
DjangoPyPI | >= 3.1, < 3.1.10 | 3.1.10 |
DjangoPyPI | >= 3.2, < 3.2.2 | 3.2.2 |
Affected products
11- Django/Djangodescription
- ghsa-coords8 versionspkg:pypi/djangopkg:bitnami/djangopkg:rpm/suse/python-Django&distro=SUSE%20Package%20Hub%2015%20SP3pkg:rpm/opensuse/python-Django&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python-Django&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django5&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django4&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django6&distro=openSUSE%20Tumbleweed
>= 2.2, < 2.2.22+ 7 more
- (no CPE)range: >= 2.2, < 2.2.22
- (no CPE)range: >= 2.2.0, < 2.2.22
- (no CPE)range: < 2.2.28-bp153.2.3.1
- (no CPE)range: < 2.2.28-bp153.2.3.1
- (no CPE)range: < 3.2.7-2.3
- (no CPE)range: < 5.2.16-1.1
- (no CPE)range: < 4.2.14-1.1
- (no CPE)range: < 6.0-1.1
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
16- www.openwall.com/lists/oss-security/2021/05/06/1nvdMailing ListPatchThird Party AdvisoryWEB
- docs.djangoproject.com/en/3.2/releases/security/nvdPatchVendor Advisory
- www.djangoproject.com/weblog/2021/may/06/security-releases/nvdPatchVendor Advisory
- github.com/advisories/GHSA-qm57-vhq3-3fwfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-32052ghsaADVISORY
- security.netapp.com/advisory/ntap-20210611-0002/nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cgighsaWEB
- docs.djangoproject.com/en/3.2/releases/securityghsaWEB
- github.com/django/django/commit/e1e81aa1c4427411e3c68facdd761229ffea6f6fghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2021-8.yamlghsaWEB
- groups.google.com/forum/ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/ZVKYPHR3TKR2ESWXBPOJEKRO2OSJRZUEghsaWEB
- security.netapp.com/advisory/ntap-20210611-0002ghsaWEB
- www.djangoproject.com/weblog/2021/may/06/security-releasesghsaWEB
- groups.google.com/forum/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZVKYPHR3TKR2ESWXBPOJEKRO2OSJRZUE/nvd
News mentions
0No linked articles in our index yet.