CVE-2025-48432
low
CVSS v3
—
CVSS v2
—
VIR risk
2.5
Description
An issue was discovered in Django 5.2 before 5.2.2, 5.1 before 5.1.10, and 4.2 before 4.2.22. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-48432
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-48432.html
Vendor advisory: arch — https://security.archlinux.org/ASA-202506-6
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 5.1.11-1 | |
| sles | affected | | |
| debian | bookworm | fixed | 3:3.2.25-0+deb12u1 |
| debian | bullseye | fixed | 2:2.2.28-1~deb11u7 |
| debian | forky | fixed | 3:4.2.23-1 |
| debian | sid | fixed | 3:4.2.23-1 |
| debian | trixie | fixed | 3:4.2.23-1 |
References
- https://security.archlinux.org/ASA-202506-6
- https://nvd.nist.gov/vuln/detail/CVE-2025-48432
- https://docs.djangoproject.com/en/dev/releases/security
- https://github.com/django/django
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2025-47.yaml
- https://groups.google.com/g/django-announce
- https://www.djangoproject.com/weblog/2025/jun/04/security-releases
- https://www.djangoproject.com/weblog/2025/jun/10/bugfix-releases
- http://www.openwall.com/lists/oss-security/2025/06/04/5
- http://www.openwall.com/lists/oss-security/2025/06/10/2
- http://www.openwall.com/lists/oss-security/2025/06/10/3
- http://www.openwall.com/lists/oss-security/2025/06/10/4
- https://www.djangoproject.com/weblog/2025/jun/04/security-releases/
- https://docs.djangoproject.com/en/dev/releases/security/
- https://www.suse.com/security/cve/CVE-2025-48432.html
- https://security-tracker.debian.org/tracker/CVE-2025-48432
Verify integrity in audit chain (admin only). AS-IS.