id: PYSEC-2026-328 published: "2026-06-29T11:50:49.713473Z" modified: "2026-07-01T20:22:51.403723Z" aliases: - CVE-2026-42196 - GHSA-67qg-7284-2277 summary: django-s3file is vulnerable to relative path traversal details: "### Impact\n`S3FileMiddleware` is vulnerable to relative path traversal attacks, where an attacker can use a modified request to escape pre-signed upload locations and have the Django application load files from random locations into `request.FILES`\n\nDepending on how files are handled, this may lead to confidentiality and integrity issues.\n\n### Patches\nDjango-S3File urges all users to update to a patched version >=7.0.2." affected: - package: name: django-s3file ecosystem: PyPI purl: pkg:pypi/django-s3file ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 7.0.2 versions: - 0.1.0 - 0.1.1 - 0.1.10 - 0.1.11 - 0.1.12 - 0.1.13 - 0.1.14 - 0.1.15 - 0.1.16 - 0.1.17 - 0.1.18 - 0.1.19 - 0.1.2 - 0.1.20 - 0.1.21 - 0.1.22 - 0.1.23 - 0.1.3 - 0.1.4 - 0.1.5 - 0.1.6 - 0.1.7 - 0.1.8 - 0.1.9 - 0.2.0 - 0.3.0 - 0.3.1 - 0.3.2 - 0.3.3 - 0.3.4 - 0.3.5 - 0.3.6 - 0.3.7 - 0.4.0 - 0.4.1 - 0.5.0 - 0.5.1 - 0.5.2 - 0.5.3 - 0.5.4 - 0.6.0 - 0.6.1 - 0.6.2 - 1.0.0 - 1.0.1 - 1.0.2 - 1.1.0 - 1.2.0 - 1.2.1 - 2.0.0 - 3.0.0 - 3.0.1 - 3.0.2 - 3.0.3 - 3.0.4 - 3.0.5 - 4.0.0 - 4.0.1 - 4.0.2 - 4.1.0 - 4.2.0 - 5.0.0 - 5.0.1 - 5.0.2 - 5.0.4 - 5.0.5 - 5.0.6 - 5.1.0 - 5.1.1 - 5.1.2 - 5.1.3 - 5.2.0 - 5.3.0 - 5.4.0 - 5.5.0 - 5.5.1 - 5.5.2 - 5.5.3 - 5.5.4 - 5.5.5 - 5.5.7 - 6.0.1 - 7.0.0 - 7.0.1 references: - type: WEB url: https://github.com/codingjoe/django-s3file/security/advisories/GHSA-67qg-7284-2277 - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2026-42196 - type: PACKAGE url: https://github.com/codingjoe/django-s3file - type: PACKAGE url: https://pypi.org/project/django-s3file - type: ADVISORY url: https://github.com/advisories/GHSA-67qg-7284-2277 severity: - type: CVSS_V4 score: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N