[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2021-31542":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":40,"aliases":41,"duplicate_of":9,"upstream":45,"downstream":46,"duplicates":79,"related":80,"reserved_at":9,"published_at":89,"modified_at":90,"state":91,"summary":92,"references_raw":101,"kevs":209,"epss":210,"epss_history":213,"metrics":469,"affected":484},"CVE-2021-31542","In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-22","Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.","weakness","Stable","Base","High",[20,24,28,32,36],{"id":21,"name":22,"techniques":23},"CAPEC-126","Path Traversal",[],{"id":25,"name":26,"techniques":27},"CAPEC-64","Using Slashes and URL Encoding Combined to Bypass Validation Logic",[],{"id":29,"name":30,"techniques":31},"CAPEC-76","Manipulating Web Input to File System Calls",[],{"id":33,"name":34,"techniques":35},"CAPEC-78","Using Escaped Slashes in Alternate Encoding",[],{"id":37,"name":38,"techniques":39},"CAPEC-79","Using Slashes in Alternate Encoding",[],[],[42,43,44],"GHSA-rxjp-mfm9-w4wr","BIT-django-2021-31542","PYSEC-2021-7",[],[47,49,51,53,55,57,59,61,63,65,67,69,71,73,75,77],{"_key":48},"RHSA-2021:5070",{"_key":50},"SUSE-SU-2021:1962-1",{"_key":52},"SUSE-SU-2021:1963-1",{"_key":54},"SUSE-SU-2021:2554-1",{"_key":56},"UBUNTU-CVE-2021-31542",{"_key":58},"USN-4932-1",{"_key":60},"OPENSUSE-SU-2024:11205-1",{"_key":62},"OPENSUSE-SU-2024:13887-1",{"_key":64},"OPENSUSE-SU-2024:14208-1",{"_key":66},"DLA-2651-1",{"_key":68},"DLA-3744-1",{"_key":70},"OPENSUSE-SU-2026:10005-1",{"_key":72},"MGASA-2021-0356",{"_key":74},"DEBIAN-CVE-2021-31542",{"_key":76},"RHSA-2021:4702",{"_key":78},"USN-4932-2",[],[81,82,83,84,85,86,87,88],{"_key":72},{"_key":50},{"_key":52},{"_key":54},{"_key":60},{"_key":62},{"_key":64},{"_key":70},"2021-05-05T00:00:00.000Z","2024-08-03T23:03:33.545Z","Modified",{"cisa_kev":93,"cisa_ransomware":93,"cisa_vendor":9,"epss_severity":94,"epss_score":95,"severity":96,"severity_score":97,"severity_version":98,"severity_source":99,"severity_vector":100,"severity_status":91},false,"low",0.04357,"high",7.5,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",[102,109,115,121,127,131,135,139,143,147,151,155,160,164,168,172,176,180,184,188,192,197,201,205],{"url":103,"sources":104,"tags":107},"https://groups.google.com/forum/#%21forum/django-announce",[105,99,106],"cve.org","osv_pypi",[108],"WEB",{"url":110,"sources":111,"tags":112},"https://docs.djangoproject.com/en/3.2/releases/security/",[105,99,106],[113,114,108],"Patch","Vendor Advisory",{"url":116,"sources":117,"tags":118},"http://www.openwall.com/lists/oss-security/2021/05/04/3",[105,99,106],[119,113,120,108],"Mailing List","Third Party Advisory",{"url":122,"sources":123,"tags":124},"https://www.djangoproject.com/weblog/2021/may/04/security-releases/",[105,99,106],[125,114,126],"Release Notes","ARTICLE",{"url":128,"sources":129,"tags":130},"https://lists.debian.org/debian-lts-announce/2021/05/msg00005.html",[105,99,106],[119,120,108],{"url":132,"sources":133,"tags":134},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZVKYPHR3TKR2ESWXBPOJEKRO2OSJRZUE/",[105,99],[114],{"url":136,"sources":137,"tags":138},"https://security.netapp.com/advisory/ntap-20210618-0001/",[105,99],[120],{"url":140,"sources":141,"tags":142},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV/",[105,99],[114],{"url":144,"sources":145,"tags":146},"https://github.com/django/django/commit/04ac1624bdc2fa737188401757cf95ced122d26d",[105,99,106],[108],{"url":148,"sources":149,"tags":150},"https://github.com/django/django/commit/25d84d64122c15050a0ee739e859f22ddab5ac48",[105,99,106],[108],{"url":152,"sources":153,"tags":154},"https://github.com/django/django/commit/c98f446c188596d4ba6de71d1b77b4a6c5c2a007",[105,99,106],[108],{"url":156,"sources":157,"tags":158},"https://nvd.nist.gov/vuln/detail/CVE-2021-31542",[106],[159],"Advisory",{"url":161,"sources":162,"tags":163},"https://www.djangoproject.com/weblog/2021/may/04/security-releases",[106],[108],{"url":165,"sources":166,"tags":167},"https://security.netapp.com/advisory/ntap-20210618-0001",[106],[108],{"url":169,"sources":170,"tags":171},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVKYPHR3TKR2ESWXBPOJEKRO2OSJRZUE",[106],[108],{"url":173,"sources":174,"tags":175},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV",[106],[108],{"url":177,"sources":178,"tags":179},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZVKYPHR3TKR2ESWXBPOJEKRO2OSJRZUE",[106],[108],{"url":181,"sources":182,"tags":183},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV",[106],[108],{"url":185,"sources":186,"tags":187},"https://groups.google.com/forum/#!forum/django-announce",[106],[108],{"url":189,"sources":190,"tags":191},"https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2021-7.yaml",[106],[108],{"url":193,"sources":194,"tags":195},"https://github.com/django/django",[106],[196],"PACKAGE",{"url":198,"sources":199,"tags":200},"https://github.com/advisories/GHSA-rxjp-mfm9-w4wr",[106],[159],{"url":202,"sources":203,"tags":204},"https://docs.djangoproject.com/en/3.2/releases/security",[106],[108],{"url":206,"sources":207,"tags":208},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVKYPHR3TKR2ESWXBPOJEKRO2OSJRZUE/",[106],[108],[],{"date":211,"score":95,"percentile":212},"2026-06-04",0.89129,[214,218,220,222,225,228,231,233,235,239,242,245,248,251,253,257,260,263,266,268,271,273,276,279,281,284,287,289,292,295,297,300,302,304,306,308,311,314,317,320,322,325,328,331,334,337,340,343,346,349,352,356,359,362,366,369,372,375,378,381,384,387,390,393,395,398,401,404,407,410,412,414,417,420,423,425,429,432,435,438,441,444,447,450,453,456,459,461,463,466],{"date":215,"score":216,"percentile":217},"2025-11-04",0.06384,0.90582,{"date":219,"score":216,"percentile":217},"2025-11-05",{"date":221,"score":216,"percentile":217},"2025-11-06",{"date":223,"score":216,"percentile":224},"2025-11-07",0.90591,{"date":226,"score":216,"percentile":227},"2025-11-08",0.90592,{"date":229,"score":216,"percentile":230},"2025-11-09",0.9059,{"date":232,"score":216,"percentile":224},"2025-11-10",{"date":234,"score":216,"percentile":230},"2025-11-11",{"date":236,"score":237,"percentile":238},"2025-11-12",0.06886,0.90973,{"date":240,"score":237,"percentile":241},"2025-11-13",0.90975,{"date":243,"score":237,"percentile":244},"2025-11-14",0.90977,{"date":246,"score":237,"percentile":247},"2025-11-15",0.90974,{"date":249,"score":237,"percentile":250},"2025-11-16",0.9098,{"date":252,"score":237,"percentile":244},"2025-11-17",{"date":254,"score":255,"percentile":256},"2025-11-18",0.03831,0.8701,{"date":258,"score":255,"percentile":259},"2025-11-19",0.87012,{"date":261,"score":255,"percentile":262},"2025-11-20",0.87016,{"date":264,"score":237,"percentile":265},"2025-11-21",0.90984,{"date":267,"score":237,"percentile":265},"2025-11-22",{"date":269,"score":237,"percentile":270},"2025-11-23",0.90987,{"date":272,"score":237,"percentile":270},"2025-11-24",{"date":274,"score":237,"percentile":275},"2025-11-25",0.90989,{"date":277,"score":237,"percentile":278},"2025-11-26",0.90988,{"date":280,"score":237,"percentile":278},"2025-11-27",{"date":282,"score":237,"percentile":283},"2025-11-28",0.90979,{"date":285,"score":237,"percentile":286},"2025-11-29",0.91014,{"date":288,"score":237,"percentile":286},"2025-11-30",{"date":290,"score":237,"percentile":291},"2025-12-01",0.91065,{"date":293,"score":237,"percentile":294},"2025-12-02",0.91063,{"date":296,"score":237,"percentile":291},"2025-12-03",{"date":298,"score":237,"percentile":299},"2025-12-04",0.9101,{"date":301,"score":237,"percentile":286},"2025-12-05",{"date":303,"score":237,"percentile":286},"2025-12-06",{"date":305,"score":237,"percentile":299},"2025-12-07",{"date":307,"score":237,"percentile":299},"2025-12-08",{"date":309,"score":237,"percentile":310},"2025-12-09",0.91013,{"date":312,"score":237,"percentile":313},"2025-12-10",0.91019,{"date":315,"score":237,"percentile":316},"2025-12-11",0.91026,{"date":318,"score":237,"percentile":319},"2025-12-12",0.91029,{"date":321,"score":237,"percentile":313},"2025-12-13",{"date":323,"score":237,"percentile":324},"2025-12-14",0.91018,{"date":326,"score":237,"percentile":327},"2025-12-15",0.91021,{"date":329,"score":237,"percentile":330},"2025-12-16",0.9103,{"date":332,"score":237,"percentile":333},"2025-12-17",0.91039,{"date":335,"score":237,"percentile":336},"2025-12-18",0.91042,{"date":338,"score":237,"percentile":339},"2025-12-19",0.91043,{"date":341,"score":237,"percentile":342},"2025-12-20",0.91044,{"date":344,"score":237,"percentile":345},"2025-12-21",0.91053,{"date":347,"score":237,"percentile":348},"2025-12-22",0.91049,{"date":350,"score":237,"percentile":351},"2025-12-23",0.91059,{"date":353,"score":354,"percentile":355},"2025-12-24",0.05192,0.89571,{"date":357,"score":354,"percentile":358},"2025-12-25",0.89582,{"date":360,"score":354,"percentile":361},"2025-12-26",0.89581,{"date":363,"score":364,"percentile":365},"2025-12-27",0.04412,0.88697,{"date":367,"score":354,"percentile":368},"2025-12-28",0.89575,{"date":370,"score":354,"percentile":371},"2025-12-29",0.89574,{"date":373,"score":354,"percentile":374},"2025-12-30",0.8958,{"date":376,"score":354,"percentile":377},"2025-12-31",0.89588,{"date":379,"score":354,"percentile":380},"2026-01-01",0.89655,{"date":382,"score":354,"percentile":383},"2026-01-02",0.89648,{"date":385,"score":354,"percentile":386},"2026-01-03",0.89646,{"date":388,"score":354,"percentile":389},"2026-01-04",0.89587,{"date":391,"score":354,"percentile":392},"2026-01-05",0.89584,{"date":394,"score":354,"percentile":377},"2026-01-06",{"date":396,"score":354,"percentile":397},"2026-01-07",0.89592,{"date":399,"score":354,"percentile":400},"2026-01-08",0.89596,{"date":402,"score":354,"percentile":403},"2026-01-09",0.89598,{"date":405,"score":354,"percentile":406},"2026-01-10",0.89599,{"date":408,"score":354,"percentile":409},"2026-01-11",0.8959,{"date":411,"score":354,"percentile":409},"2026-01-12",{"date":413,"score":354,"percentile":389},"2026-01-13",{"date":415,"score":354,"percentile":416},"2026-01-14",0.89602,{"date":418,"score":354,"percentile":419},"2026-01-15",0.89603,{"date":421,"score":354,"percentile":422},"2026-01-16",0.89607,{"date":424,"score":354,"percentile":422},"2026-01-17",{"date":426,"score":427,"percentile":428},"2026-01-18",0.05625,0.90071,{"date":430,"score":427,"percentile":431},"2026-01-19",0.90072,{"date":433,"score":427,"percentile":434},"2026-01-20",0.90073,{"date":436,"score":427,"percentile":437},"2026-01-21",0.90075,{"date":439,"score":427,"percentile":440},"2026-01-22",0.90079,{"date":442,"score":427,"percentile":443},"2026-01-23",0.90087,{"date":445,"score":427,"percentile":446},"2026-01-24",0.90093,{"date":448,"score":427,"percentile":449},"2026-01-25",0.90092,{"date":451,"score":354,"percentile":452},"2026-01-26",0.89631,{"date":454,"score":354,"percentile":455},"2026-01-27",0.89632,{"date":457,"score":354,"percentile":458},"2026-01-28",0.89638,{"date":460,"score":354,"percentile":458},"2026-01-29",{"date":462,"score":354,"percentile":458},"2026-01-30",{"date":464,"score":354,"percentile":465},"2026-01-31",0.89636,{"date":467,"score":354,"percentile":468},"2026-02-01",0.897,[470,479],{"source":99,"cvss_v2_0":471,"cvss_v3_0":9,"cvss_v3_1":476,"cvss_v4_0":9},{"baseScore":472,"baseSeverity":9,"vectorString":473,"impactScore":474,"exploitabilityScore":475},5,"AV:N/AC:L/Au:N/C:P/I:N/A:N",2.9,10,{"baseScore":97,"baseSeverity":477,"vectorString":100,"impactScore":478,"exploitabilityScore":475},"HIGH",6,{"source":106,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":480,"cvss_v4_0":481},{"baseScore":97,"baseSeverity":9,"vectorString":100,"impactScore":478,"exploitabilityScore":475},{"baseScore":482,"baseSeverity":9,"vectorString":483,"impactScore":9,"exploitabilityScore":9},8.7,"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",[485,494,515,523],{"ecosystem":9,"name":486,"vendor":487,"product":488,"cpe_part":489,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":490},"debian linux","debian","debian_linux","o",[491],{"version":492,"is_range":93,"range_type":493,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"9.0","cpe",{"ecosystem":9,"name":495,"vendor":496,"product":497,"cpe_part":498,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":499},"Django","djangoproject","django","a",[500,507,511],{"version":501,"is_range":502,"range_type":493,"version_start":503,"version_start_type":504,"version_end":505,"version_end_type":506,"fixed_in":9},"gte2.2_lt2.2.21",true,"2.2","including","2.2.21","excluding",{"version":508,"is_range":502,"range_type":493,"version_start":509,"version_start_type":504,"version_end":510,"version_end_type":506,"fixed_in":9},"gte3.1_lt3.1.9","3.1","3.1.9",{"version":512,"is_range":502,"range_type":493,"version_start":513,"version_start_type":504,"version_end":514,"version_end_type":506,"fixed_in":9},"gte3.2_lt3.2.1","3.2","3.2.1",{"ecosystem":9,"name":516,"vendor":517,"product":516,"cpe_part":489,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":518},"fedora","fedoraproject",[519,521],{"version":520,"is_range":93,"range_type":493,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"34",{"version":522,"is_range":93,"range_type":493,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"35",{"ecosystem":524,"name":497,"vendor":524,"product":497,"cpe_part":9,"purl_type":525,"purl_namespace":9,"purl_name":497,"source":9,"versions":526},"PyPI","pypi",[527,530,533],{"version":528,"is_range":502,"range_type":529,"version_start":503,"version_start_type":504,"version_end":505,"version_end_type":506,"fixed_in":9},"gte2_2_lt2_2_21","ecosystem",{"version":531,"is_range":502,"range_type":529,"version_start":532,"version_start_type":504,"version_end":510,"version_end_type":506,"fixed_in":9},"gte3_0_lt3_1_9","3.0",{"version":534,"is_range":502,"range_type":529,"version_start":513,"version_start_type":504,"version_end":514,"version_end_type":506,"fixed_in":9},"gte3_2_lt3_2_1"]