CVE-2025-59682

unknown
Published 2025-10-01 · Modified 2026-02-04
CVSS v3
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v2
VIR risk

Description

Django vulnerable to partial directory traversal via archives

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-59682

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-59682.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed3:3.2.25-0+deb12u1
debian debianbullseyefixed2:2.2.28-1~deb11u9
debian debianforkyfixed3:4.2.25-1
debian debiansidfixed3:4.2.25-1
debian debiantrixiefixed3:4.2.27-0+deb13u1

Package impact

EcosystemPackageVulnerableFixed
python PyPIdjango>=4.2,<4.2.254.2.25
python PyPIdjango>=5.1,<5.1.135.1.13
python PyPIdjango>=5.2,<5.2.75.2.7

References

Verify integrity in audit chain (admin only). AS-IS.