| Package | Installed | Affected | Info |
|---|---|---|---|
| djangorestframework | 3.14.0 | <3.15.2 |
show Affected versions of the package djangorestframework are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags. |
| Package | Installed | Affected | Info |
|---|---|---|---|
| djangorestframework | 3.14.0 | <3.15.2 |
show Affected versions of the package djangorestframework are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags. |
| Package | Installed | Affected | Info |
|---|---|---|---|
| djangorestframework | 3.14.0 | <3.15.2 |
show Affected versions of the package djangorestframework are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags. |
| Package | Installed | Affected | Info |
|---|---|---|---|
| djangorestframework | 3.14.0 | <3.15.2 |
show Affected versions of the package djangorestframework are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags. |
| Package | Installed | Affected | Info |
|---|---|---|---|
| djangorestframework | 3.14.0 | <3.15.2 |
show Affected versions of the package djangorestframework are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags. |
| Package | Installed | Affected | Info |
|---|---|---|---|
| gunicorn | 20.1.0 | <22.0.0 |
show Affected versions of the gunicorn package are vulnerable to HTTP Request/Response Smuggling due to improper validation of the Transfer-Encoding header that enables a TE.CL desynchronisation condition. Gunicorn’s HTTP parser does not consistently enforce RFC semantics when parsing conflicting or unsupported request framing—such as messages containing both Transfer-Encoding and Content-Length—so the backend may fall back to Content-Length while an intermediary treats the message as chunked. |
| gunicorn | 20.1.0 | <22.0.0 |
show Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability allows for a range of attacks including cache poisoning, session manipulation, and data exposure. |
| djangorestframework | 3.14.0 | <3.15.2 |
show Affected versions of the package djangorestframework are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags. |
https://pyup.io/repos/github/agconti/cookiecutter-django-rest/python-3-shield.svg
[](https://pyup.io/repos/github/agconti/cookiecutter-django-rest/)
.. image:: https://pyup.io/repos/github/agconti/cookiecutter-django-rest/python-3-shield.svg
:target: https://pyup.io/repos/github/agconti/cookiecutter-django-rest/
:alt: Python 3
<a href="https://pyup.io/repos/github/agconti/cookiecutter-django-rest/"><img src="https://pyup.io/repos/github/agconti/cookiecutter-django-rest/shield.svg" alt="Python 3" /></a>
!https://pyup.io/repos/github/agconti/cookiecutter-django-rest/python-3-shield.svg(Python 3)!:https://pyup.io/repos/github/agconti/cookiecutter-django-rest/
{<img src="https://pyup.io/repos/github/agconti/cookiecutter-django-rest/python-3-shield.svg" alt="Python 3" />}[https://pyup.io/repos/github/agconti/cookiecutter-django-rest/]
https://pyup.io/repos/github/agconti/cookiecutter-django-rest/shield.svg
[](https://pyup.io/repos/github/agconti/cookiecutter-django-rest/)
.. image:: https://pyup.io/repos/github/agconti/cookiecutter-django-rest/shield.svg
:target: https://pyup.io/repos/github/agconti/cookiecutter-django-rest/
:alt: Updates
<a href="https://pyup.io/repos/github/agconti/cookiecutter-django-rest/"><img src="https://pyup.io/repos/github/agconti/cookiecutter-django-rest/shield.svg" alt="Updates" /></a>
!https://pyup.io/repos/github/agconti/cookiecutter-django-rest/shield.svg(Updates)!:https://pyup.io/repos/github/agconti/cookiecutter-django-rest/
{<img src="https://pyup.io/repos/github/agconti/cookiecutter-django-rest/shield.svg" alt="Updates" />}[https://pyup.io/repos/github/agconti/cookiecutter-django-rest/]