VYPR
Critical severityNVD Advisory· Published May 7, 2023· Updated Jan 29, 2025

CVE-2023-31047

CVE-2023-31047

Description

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
DjangoPyPI
>= 3.2a1, < 3.2.193.2.19
DjangoPyPI
>= 4.0a1, < 4.1.94.1.9
DjangoPyPI
>= 4.2a1, < 4.2.14.2.1

Affected products

6

Patches

Vulnerability mechanics

Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

18

News mentions

0

No linked articles in our index yet.