django-anymail
Django email backends and webhooks for Amazon SES, Brevo, MailerSend, Mailgun, Mailjet, Mailtrap, Postmark, Postal, Resend, Scaleway TEM, SendGrid, SparkPost, Unisender Go and more
Activity
- Latest release
- 1w ago
- Total releases
- 65
- Cadence
- ~2 months
- Last 12 months
- 4
Reach
- Stars
- 1.9k
Details
- License
- BSD-3-Clause
- First release
- Mar 10, 2016
| Version | Released | |
|---|---|---|
15.2
minor
| ||
15.1
minor
| ||
15.0
major
| ||
14.0
major
| ||
13.1
minor
| ||
13.0.1
patch
| ||
13.0
major
| ||
12.0
major
| ||
11.1
minor
| ||
11.0.1
patch
| ||
11.0
major
| ||
10.3
minor
| ||
10.2
minor
| ||
10.1
minor
| ||
10.0
major
| ||
9.2
minor
| ||
9.1
minor
| ||
9.0
major
| ||
8.6
minor
| ||
8.5
minor
| ||
8.4
minor
| ||
8.3
minor
| ||
8.2
minor
| ||
8.1
minor
| ||
8.0
major
| ||
7.2.1
patch
| ||
7.2
minor
| ||
7.1.0
minor
| ||
7.0.0
major
| ||
6.1.0
minor
| ||
6.0.1
patch
| ||
6.0
major
| ||
5.0
major
| ||
4.3
minor
| ||
4.2
minor
| ||
4.1
minor
| ||
4.0
major
| ||
3.0
major
| ||
2.2
minor
| ||
2.1
minor
| ||
2.0
major
| ||
1.4
minor
| ||
1.3
minor
1 CVE
CVE-2018-1000089
GHSA-qh9x-mc42-vg4g
PYSEC-2018-46
May 14, 2022
django-anymail Includes Sensitive Information in Log Files
Critical
Network
Low
None
None
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4. Affected versions
0.10
0.11
0.11.1
0.2
0.3
0.3.1
0.4.1
0.4.2
0.5
0.6
0.6.1
0.7
+ 8 more Show less
0.8
0.9
1.0
1.0rc0
1.1
1.2
1.2.1
1.3
Fixed in
1.4
References
Updated Nov 26, 2024 · Source: OSV.dev | ||
1.2.1
patch
1 CVE
CVE-2018-1000089
GHSA-qh9x-mc42-vg4g
PYSEC-2018-46
May 14, 2022
django-anymail Includes Sensitive Information in Log Files
Critical
Network
Low
None
None
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4. Affected versions
0.10
0.11
0.11.1
0.2
0.3
0.3.1
0.4.1
0.4.2
0.5
0.6
0.6.1
0.7
+ 8 more Show less
0.8
0.9
1.0
1.0rc0
1.1
1.2
1.2.1
1.3
Fixed in
1.4
References
Updated Nov 26, 2024 · Source: OSV.dev | ||
1.2
minor
2 CVEs
CVE-2018-1000089
GHSA-qh9x-mc42-vg4g
PYSEC-2018-46
May 14, 2022
django-anymail Includes Sensitive Information in Log Files
Critical
Network
Low
None
None
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4. Affected versions
0.10
0.11
0.11.1
0.2
0.3
0.3.1
0.4.1
0.4.2
0.5
0.6
0.6.1
0.7
+ 8 more Show less
0.8
0.9
1.0
1.0rc0
1.1
1.2
1.2.1
1.3
Fixed in
1.4
References
Updated Nov 26, 2024 · Source: OSV.dev
CVE-2018-6596
GHSA-hxf9-7h4c-f5jv
PYSEC-2018-7
Jul 12, 2018
Django-Anymail prone to a timing attack
Critical
Network
Low
None
None
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events. Affected versions
0.1
0.1.dev0
0.1.dev1
0.1.dev2
0.10
0.11
0.11.1
0.2
0.3
0.3.1
0.4.1
0.4.2
+ 10 more Show less
0.5
0.6
0.6.1
0.7
0.8
0.9
1.0
1.0rc0
1.1
1.2
Fixed in
1.2.1
References
Updated Feb 16, 2025 · Source: OSV.dev | ||
1.1
minor
2 CVEs
CVE-2018-1000089
GHSA-qh9x-mc42-vg4g
PYSEC-2018-46
May 14, 2022
django-anymail Includes Sensitive Information in Log Files
Critical
Network
Low
None
None
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4. Affected versions
0.10
0.11
0.11.1
0.2
0.3
0.3.1
0.4.1
0.4.2
0.5
0.6
0.6.1
0.7
+ 8 more Show less
0.8
0.9
1.0
1.0rc0
1.1
1.2
1.2.1
1.3
Fixed in
1.4
References
Updated Nov 26, 2024 · Source: OSV.dev
CVE-2018-6596
GHSA-hxf9-7h4c-f5jv
PYSEC-2018-7
Jul 12, 2018
Django-Anymail prone to a timing attack
Critical
Network
Low
None
None
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events. Affected versions
0.1
0.1.dev0
0.1.dev1
0.1.dev2
0.10
0.11
0.11.1
0.2
0.3
0.3.1
0.4.1
0.4.2
+ 10 more Show less
0.5
0.6
0.6.1
0.7
0.8
0.9
1.0
1.0rc0
1.1
1.2
Fixed in
1.2.1
References
Updated Feb 16, 2025 · Source: OSV.dev | ||
1.0
major
2 CVEs
CVE-2018-1000089
GHSA-qh9x-mc42-vg4g
PYSEC-2018-46
May 14, 2022
django-anymail Includes Sensitive Information in Log Files
Critical
Network
Low
None
None
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4. Affected versions
0.10
0.11
0.11.1
0.2
0.3
0.3.1
0.4.1
0.4.2
0.5
0.6
0.6.1
0.7
+ 8 more Show less
0.8
0.9
1.0
1.0rc0
1.1
1.2
1.2.1
1.3
Fixed in
1.4
References
Updated Nov 26, 2024 · Source: OSV.dev
CVE-2018-6596
GHSA-hxf9-7h4c-f5jv
PYSEC-2018-7
Jul 12, 2018
Django-Anymail prone to a timing attack
Critical
Network
Low
None
None
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events. Affected versions
0.1
0.1.dev0
0.1.dev1
0.1.dev2
0.10
0.11
0.11.1
0.2
0.3
0.3.1
0.4.1
0.4.2
+ 10 more Show less
0.5
0.6
0.6.1
0.7
0.8
0.9
1.0
1.0rc0
1.1
1.2
Fixed in
1.2.1
References
Updated Feb 16, 2025 · Source: OSV.dev | ||
1.0rc0
pre
2 CVEs
CVE-2018-1000089
GHSA-qh9x-mc42-vg4g
PYSEC-2018-46
May 14, 2022
django-anymail Includes Sensitive Information in Log Files
Critical
Network
Low
None
None
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4. Affected versions
0.10
0.11
0.11.1
0.2
0.3
0.3.1
0.4.1
0.4.2
0.5
0.6
0.6.1
0.7
+ 8 more Show less
0.8
0.9
1.0
1.0rc0
1.1
1.2
1.2.1
1.3
Fixed in
1.4
References
Updated Nov 26, 2024 · Source: OSV.dev
CVE-2018-6596
GHSA-hxf9-7h4c-f5jv
PYSEC-2018-7
Jul 12, 2018
Django-Anymail prone to a timing attack
Critical
Network
Low
None
None
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events. Affected versions
0.1
0.1.dev0
0.1.dev1
0.1.dev2
0.10
0.11
0.11.1
0.2
0.3
0.3.1
0.4.1
0.4.2
+ 10 more Show less
0.5
0.6
0.6.1
0.7
0.8
0.9
1.0
1.0rc0
1.1
1.2
Fixed in
1.2.1
References
Updated Feb 16, 2025 · Source: OSV.dev | ||
0.11.1
patch
2 CVEs
CVE-2018-1000089
GHSA-qh9x-mc42-vg4g
PYSEC-2018-46
May 14, 2022
django-anymail Includes Sensitive Information in Log Files
Critical
Network
Low
None
None
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4. Affected versions
0.10
0.11
0.11.1
0.2
0.3
0.3.1
0.4.1
0.4.2
0.5
0.6
0.6.1
0.7
+ 8 more Show less
0.8
0.9
1.0
1.0rc0
1.1
1.2
1.2.1
1.3
Fixed in
1.4
References
Updated Nov 26, 2024 · Source: OSV.dev
CVE-2018-6596
GHSA-hxf9-7h4c-f5jv
PYSEC-2018-7
Jul 12, 2018
Django-Anymail prone to a timing attack
Critical
Network
Low
None
None
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events. Affected versions
0.1
0.1.dev0
0.1.dev1
0.1.dev2
0.10
0.11
0.11.1
0.2
0.3
0.3.1
0.4.1
0.4.2
+ 10 more Show less
0.5
0.6
0.6.1
0.7
0.8
0.9
1.0
1.0rc0
1.1
1.2
Fixed in
1.2.1
References
Updated Feb 16, 2025 · Source: OSV.dev | ||
0.11
minor
2 CVEs
CVE-2018-1000089
GHSA-qh9x-mc42-vg4g
PYSEC-2018-46
May 14, 2022
django-anymail Includes Sensitive Information in Log Files
Critical
Network
Low
None
None
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4. Affected versions
0.10
0.11
0.11.1
0.2
0.3
0.3.1
0.4.1
0.4.2
0.5
0.6
0.6.1
0.7
+ 8 more Show less
0.8
0.9
1.0
1.0rc0
1.1
1.2
1.2.1
1.3
Fixed in
1.4
References
Updated Nov 26, 2024 · Source: OSV.dev
CVE-2018-6596
GHSA-hxf9-7h4c-f5jv
PYSEC-2018-7
Jul 12, 2018
Django-Anymail prone to a timing attack
Critical
Network
Low
None
None
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events. Affected versions
0.1
0.1.dev0
0.1.dev1
0.1.dev2
0.10
0.11
0.11.1
0.2
0.3
0.3.1
0.4.1
0.4.2
+ 10 more Show less
0.5
0.6
0.6.1
0.7
0.8
0.9
1.0
1.0rc0
1.1
1.2
Fixed in
1.2.1
References
Updated Feb 16, 2025 · Source: OSV.dev |