An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank N05ec@LZU-DSLab for reporting this issue.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-django | Apr 10, 2026 | Apr 7, 2026 |
| Suse | — | Upgrade python3-djangoUpgrade python313-DjangoUpgrade python3-djangorestframeworkUpgrade python311-djangorestframework | Apr 20, 2026 | Apr 20, 2026 |
| Ubuntu | — | Upgrade python3-djangoUpgrade python-django (Ubuntu Pro)Upgrade python3-django (Ubuntu Pro) | Apr 9, 2026 | Apr 7, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub