GHSA-mm6v-q8q9-pgcf

Suggest an improvement
Source
https://github.com/advisories/GHSA-mm6v-q8q9-pgcf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-mm6v-q8q9-pgcf/GHSA-mm6v-q8q9-pgcf.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-mm6v-q8q9-pgcf
Aliases
Downstream
Published
2026-06-03T15:30:43Z
Modified
2026-07-17T21:16:27Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
Details

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15.

django.core.mail.backends.smtp.EmailBackend in Django fails to prevent reuse of a partially-initialized connection after a failed STARTTLS handshake when fail_silently=True, which allows on-path network attackers to read email content via cleartext interception.

Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Kasper Dupont for reporting this issue.

Database specific
{
    "cwe_ids":  [
        "CWE-319"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-13T17:26:39Z",
    "nvd_published_at":  "2026-06-03T14:16:47Z",
    "severity":  "LOW"
}
References

Affected packages

PyPI / django

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.2
Fixed
5.2.15

Affected versions

5.*
5.2
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
5.2.10
5.2.11
5.2.12
5.2.13
5.2.14

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-mm6v-q8q9-pgcf/GHSA-mm6v-q8q9-pgcf.json"

PyPI / django

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0
Fixed
6.0.6

Affected versions

6.*
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-mm6v-q8q9-pgcf/GHSA-mm6v-q8q9-pgcf.json"