django-registration
An extensible user-registration application for Django.
Activity
- Latest release
- 1y ago
- Total releases
- 29
- Cadence
- ~5 months
- Last 12 months
- 0
Details
- License
- BSD-3-Clause
- First release
- Nov 06, 2008
| Version | Released | |
|---|---|---|
5.2.1
minor
|
5.2.1
minor
Dependencies (2)
|
|
5.2.0a0
pre
|
5.2.0a0
pre
Dependencies (2)
|
|
5.1.0
major
|
5.1.0
major
Dependencies (2)
|
|
3.4
minor
|
3.4
minor
Dependencies (11)
+ 3 more |
|
3.3
minor
|
3.3
minor
Dependencies (2)
|
|
3.2
minor
|
3.2
minor
Dependencies (2)
|
|
3.1.2
patch
|
3.1.2
patch
Dependencies (2)
|
|
3.1.1
patch
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.1.1
patch
Dependencies (2)
|
|
3.1
minor
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.1
minor
Dependencies (2)
|
|
3.0.1
patch
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.0.1
patch
Dependencies (2)
|
|
3.0
major
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.0
major
Dependencies (2)
|
|
2.5.2
patch
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.5.2
patch
Dependencies (2)
|
|
2.5.1
patch
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.5.1
patch
Dependencies (2)
|
|
2.5
minor
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.5
minor
Dependencies (2)
|
|
2.4.1
patch
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.4.1
patch
Dependencies (2)
|
|
2.4
minor
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.4
minor
Dependencies (2)
|
|
2.3
minor
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.3
minor
Dependencies (2)
|
|
2.2
minor
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.2
minor
|
|
2.1.2
patch
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.1.2
patch
|
|
2.1.1
patch
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.1.1
patch
|
|
2.1
minor
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.1
minor
|
|
2.0.4
patch
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.0.4
patch
|
|
2.0.3
patch
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.0.3
patch
|
|
2.0.2
patch
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.0.2
patch
|
|
2.0.1
patch
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.0.1
patch
|
|
2.0
major
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.0
major
|
|
1.0
major
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.0
major
|
|
0.8
minor
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.8
minor
|
|
0.7
initial
1 CVE
CVE-2021-21416
GHSA-58c7-px5v-82hh
PYSEC-2021-11
Apr 06, 2021
Potential sensitive information disclosed in error reports
Low
Network
Low
High
django-registration is a user-registration application for Django. ImpactThe django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires the following conditions:
Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password). PatchesAs of version 3.1.2, django-registration properly applies Django's Note that as applied, this filters all HTTP request data from error reports. To selectively allow some fields but not others, see Django's own documentation (in references) and the notes below for how to apply WorkaroundsUsers who cannot upgrade quickly can apply the
References
Affected versions
0.5
0.6
0.7
0.8
1.0
2.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1
2.1.1
+ 12 more Show less
2.1.2
2.2
2.3
2.4
2.4.1
2.5
2.5.1
2.5.2
3.0
3.0.1
3.1
3.1.1
Fixed in
3.1.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.7
initial
|