news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2025-13473

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
5.3 Medium
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Risk score
42.4
Published
2026-02-03
Status
Analyzed

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers.modwsgi.check_password()` function for authentication via `mod_wsgi` allows remote attackers to enumerate users via a timing attack. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Stackered for reporting this issue.

Weaknesses

CWE-208

Coverage 1

Advisories and references