affected: - package: ecosystem: PyPI name: django purl: pkg:pypi/django ranges: - events: - introduced: '4.2' - fixed: 4.2.28 - introduced: '5.2' - fixed: 5.2.11 - introduced: '6.0' - fixed: 6.0.2 type: ECOSYSTEM versions: - '4.2' - 4.2.1 - 4.2.10 - 4.2.11 - 4.2.12 - 4.2.13 - 4.2.14 - 4.2.15 - 4.2.16 - 4.2.17 - 4.2.18 - 4.2.19 - 4.2.2 - 4.2.20 - 4.2.21 - 4.2.22 - 4.2.23 - 4.2.24 - 4.2.25 - 4.2.26 - 4.2.27 - 4.2.3 - 4.2.4 - 4.2.5 - 4.2.6 - 4.2.7 - 4.2.8 - 4.2.9 - '5.2' - 5.2.1 - 5.2.10 - 5.2.2 - 5.2.3 - 5.2.4 - 5.2.5 - 5.2.6 - 5.2.7 - 5.2.8 - 5.2.9 - '6.0' - 6.0.1 aliases: - CVE-2025-13473 - GHSA-2mcm-79hx-8fxw details: |- An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers.modwsgi.check_password()` function for authentication via `mod_wsgi` allows remote attackers to enumerate users via a timing attack. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Stackered for reporting this issue. id: PYSEC-2026-42 modified: '2026-05-20T09:18:57.954995Z' published: '2026-02-03T15:16:11.593Z' references: - type: ADVISORY url: https://groups.google.com/g/django-announce - type: FIX url: https://docs.djangoproject.com/en/dev/releases/security/ - type: FIX url: https://www.djangoproject.com/weblog/2026/feb/03/security-releases/ - type: ADVISORY url: https://github.com/advisories/GHSA-2mcm-79hx-8fxw severity: - score: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N type: CVSS_V3