CVE-2025-48432
Published: 05 June 2025
Summary
CVE-2025-48432 is a medium-severity Improper Output Neutralization for Logs (CWE-117) vulnerability in Djangoproject Django. Its CVSS base score is 4.0 (Medium).
Operationally, ranked in the top 38.1% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-16951
Vulnerability details
An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to…
more
log injection or forgery when logs are viewed in terminals or processed by external systems.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.