https://seclists.org/oss-sec/2025/q4/226: Django CVE-2025-13372 and CVE-2025-64460
Published Dec 2, 2025
·Updated
Affected Software
1 affected component
Django Django
Frequently Asked Questions
1
What is the severity of CVE-2025-13372?
CVE-2025-13372 has been assigned a critical severity rating due to its potential for remote code execution.
2
How do I fix CVE-2025-13372?
To address CVE-2025-13372, upgrade to the latest version of Django as recommended in the security release notes.
3
What impact does CVE-2025-64460 have on Django applications?
CVE-2025-64460 can lead to information disclosure, which may expose sensitive data in Django applications.
4
How can I mitigate the risks associated with CVE-2025-64460?
Mitigate risks from CVE-2025-64460 by applying the security patches provided in the latest Django updates.
5
When were CVE-2025-13372 and CVE-2025-64460 published?
CVE-2025-13372 and CVE-2025-64460 were published on December 2, 2025.