django-unicorn
A magical full-stack framework for Django.
Activity
- Latest release
- 6mo ago
- Total releases
- 113
- Cadence
- ~13 days
- Last 12 months
- 6
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Jul 22, 2020
| Version | Released | |
|---|---|---|
0.67.0
minor
| ||
0.66.1
minor
1 CVE
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.65.2
patch
1 CVE
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.65.0
minor
1 CVE
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.64.0
minor
1 CVE
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.63.3
minor
1 CVE
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.62.0
minor
1 CVE
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.61.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.60.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.59.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.58.1
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.58.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.57.1
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.57.1
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.57.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.57.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.56.1
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.56.1
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.56.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.56.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.55.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.55.0
minor
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.54.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.54.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.53.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.53.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.52.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.52.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.51.1
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.51.1
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.51.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.51.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.50.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.50.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.49.2
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.49.2
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.49.1
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.49.1
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.49.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.49.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.48.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.48.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.47.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.47.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.46.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.46.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.45.1
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.45.1
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.45.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.45.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.44.1
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.44.1
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.44.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.44.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.43.1
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.43.1
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.43.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.43.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.42.1
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|
0.42.1
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.42.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.41.2
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.41.1
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.41.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.40.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.39.1
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.39.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.38.1
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.38.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.37.2
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.37.1
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.37.0
minor
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.36.1
patch
2 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
| ||
0.36.0
minor
3 CVEs
CVE-2026-31815
PYSEC-2026-2451
GHSA-ffv6-jj46-x367
Jul 13, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryComponent state manipulation is possible in Vulnerability Details: Component Access Control BypassSecurity analysis identified that the framework fails to enforce visibility boundaries defined by Vulnerability resides in:
While Django's template engine restricts rendering to registered directories, an unauthorized user can still force a component to render sensitive templates (e.g., admin layouts) from other installed applications or reset the component state by invoking the internal Proof of Concept (PoC)Attacker can overwrite the
ImpactLow severity. The risk is limited to unauthorized manipulation of component state and rendering of existing templates within the application's configured template directories. Remote Code Execution (RCE) is not possible via this vector. Affected versions
0.1.0
0.1.1
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
+ 100 more Show less
0.15.1
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.2.0
0.2.1
0.2.2
0.2.3
0.20.0
0.21.0
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.27.1
0.27.2
0.28.0
0.29.0
0.3.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.35.2
0.35.3
0.36.0
0.36.1
0.37.0
0.37.1
0.37.2
0.38.0
0.38.1
0.39.0
0.39.1
0.4.0
0.40.0
0.41.0
0.41.1
0.41.2
0.42.0
0.42.1
0.43.0
0.43.1
0.44.0
0.44.1
0.45.0
0.45.1
0.46.0
0.47.0
0.48.0
0.49.0
0.49.1
0.49.2
0.5.0
0.50.0
0.51.0
0.51.1
0.52.0
0.53.0
0.54.0
0.55.0
0.56.0
0.56.1
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.60.0
0.61.0
0.62.0
0.63.3
0.64.0
0.65.0
0.65.2
0.66.1
0.7.0
0.7.1
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.67.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-24370
PYSEC-2026-329
GHSA-g9wf-5777-gq43
Jun 29, 2026
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
Network
Low
None
None
SummaryDjango-Unicorn is vulnerable to python class pollution vulnerability, a new type of vulnerability categorized under CWE-915. The vulnerability arises from the core functionality At least five ways of vulnerability exploitation have been found, stably resulting in Cross-Site Scripting (XSS), Denial of Service (DoS), and Authentication Bypass attacks in almost every Django-Unicorn-based application. Analysis of Vulnerable FunctionBy taking a look at the vulnerable function The property is specified by a dotted form of path at the second parameter
Meanwhile, this functionality can be directly triggered by a component request, one of the core functionalities of the project, by specifying the request type as
You are now aware of that users from the remote can fully control the However, the functionality failed to count in the situation where bad actors can modify the normal path to traverse to other objects in the python runtime, by leveraging the magic attributes. For example, if the With all these techniques introduced, you can now change any global objects including, global variables/instances/classes/functions of any module that is in a chain of dependency from the component module. The next section introduces the five exploitation gadgets found so far, leading to reflected XSS, stored XSS, authentication bypass and DOS attack. It uses a locally deployed
Proof of Concept#1 Reflected Cross-Site Scripting by Overwriting bs4 HTML sanitizerDjango-Unicorn implants the
While this rule is specified in a global dictionary, you can exploit the class pollution vulnerability to overwrite it.
In this demonstration, replaced the sanitizer's
#2 Stored Cross-Site Scripting by Overwriting Unicorn Setting and Django Json Script SanitizerThere is always a script tag in the webpage. Among it, a
However, simply polluting these values can not lead to a stored XSS attack. Django by default escape some of the special characters into unicode sequences.
Going through the source code of django, you will find the actual sanitizer located at
By polluting this variable to clear it out, you finally achieve a stored XSS attack.
PoC:
#3 Stored Cross-Site Scripting by Overwriting Django Error Page Source CodeDjango by default stores its error page source code in a global variable named
By polluting this variable to XSS payload. whenever a user triggers an error in the application, such as access an unexisting resource, the attack payload fires out.
#4 Authentication Bypass by Overwriting Django Secret KeyDjango secret key is typically used to sign and verify session cookies and other security related mechanism. By polluting its runtime value to attacker intended, attacker can forge session cookies to login in to the system as any user. Even though, django-unicorn.com doesn't have an authentication layer, you can still observe a successful secret key pollution by inspecting the changed checksum in the HTTP response, since the checksum is generated by encrypting the data field in the request body with the secret key.
#5 Denial of Service by Overwriting
|











